CFNetwork in Apple OS X through 10.8.5 does not remove session cookies upon a Safari reset action, which allows physically proximate attackers to bypass intended access restrictions by leveraging an unattended workstation.
2014-02-27T01:55:03.897
2025-04-12T10:46:40.837
Deferred
CVSSv2: 3.6 (LOW)
AV:L/AC:L/Au:N/C:P/I:P/A:N
3.9
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | apple | mac_os_x | ≤ 10.8.5 | Yes |
Operating System | apple | mac_os_x | 10.8.0 | Yes |
Operating System | apple | mac_os_x | 10.8.1 | Yes |
Operating System | apple | mac_os_x | 10.8.2 | Yes |
Operating System | apple | mac_os_x | 10.8.3 | Yes |
Operating System | apple | mac_os_x | 10.8.4 | Yes |
Operating System | apple | mac_os_x | 10.8.5 | Yes |