An issue was discovered in certain Apple products. Safari before 11 is affected. The issue involves the "WebKit Storage" component. It allows attackers to bypass the Safari Private Browsing protection mechanism, and consequently obtain sensitive information about visited web sites.
CVSS Details
- CVSS 3.0 Base Score: 5.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Safari | — | Upgrade to Apple Safari version 11Uninstall Apple Safari on Windows | Sep 26, 2017 | Sep 26, 2017 |
| Debian | — | Upgrade webkit2gtk | Jul 30, 2024 | Oct 23, 2017 |
| Oracle Solaris | — | Upgrade entire/ to version 11.4-11.4.0.0.1.15.0 on Solaris 11.4 | Oct 19, 2018 | Oct 22, 2017 |
| Suse | — | Upgrade typelib-1_0-javascriptcore-4_0Upgrade webkit2gtk-4_0-injected-bundlesUpgrade libwebkit2gtk-4_0-37Upgrade typelib-1_0-webkit2webextension-4_0Upgrade webkit2gtk3-develUpgrade libwebkit2gtk3-langUpgrade libjavascriptcoregtk-4_0-18Upgrade typelib-1_0-webkit2-4_0 | Jan 26, 2018 | Oct 22, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub