CVE-2008-7296

Apple Safari - Cookie Manipulation via HTTP Set-Cookie Header

Title source: llm
STIX 2.1

Description

Apple Safari cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attackers to overwrite or delete arbitrary cookies via a Set-Cookie header in an HTTP response, related to lack of the HTTP Strict Transport Security (HSTS) includeSubDomains feature, aka a "cookie forcing" issue.

Scores

EPSS 0.0100
EPSS Percentile 59.4%

Details

CWE
CWE-264
Status published
Products (1)
apple/safari
Published Aug 09, 2011
Tracked Since Feb 18, 2026