CVE-2016-4708

Publication date

2016-09-25 10:00:00

Family

apple

State

PUBLISHED

Description

CFNetwork in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 misparses the Set-Cookie header, which allows remote attackers to obtain sensitive information via a crafted HTTP response.