CFNetwork in Apple OS X before 10.11.6 uses weak permissions for web-browser cookies, which allows local users to obtain sensitive information via unspecified vectors.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/91824 | vdb entry |
http://lists.apple.com/archives/security-announce/2016/Jul/msg00000.html | mailing list vendor advisory |
http://www.securitytracker.com/id/1036348 | vdb entry |
https://support.apple.com/HT206903 | vendor advisory |