{"api_version":"1","generated_at":"2026-07-23T12:04:54+00:00","cve":"CVE-2017-7144","urls":{"html":"https://cve.report/CVE-2017-7144","api":"https://cve.report/api/cve/CVE-2017-7144.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-7144","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-7144"},"summary":{"title":"CVE-2017-7144","description":"An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. The issue involves the \"WebKit\" component. It allows remote attackers to track Safari Private Browsing users by leveraging cookie mishandling.","state":"PUBLIC","assigner":"product-security@apple.com","published_at":"2017-10-23 01:29:00","updated_at":"2017-10-26 18:23:00"},"problem_types":["CWE-275"],"metrics":[],"references":[{"url":"http://www.securityfocus.com/bid/100991","name":"100991","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"Malformed Request","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://support.apple.com/HT208116","name":"https://support.apple.com/HT208116","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"About the security content of Safari 11 - Apple Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://support.apple.com/HT208112","name":"https://support.apple.com/HT208112","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"About the security content of iOS 11 - Apple Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1039384","name":"1039384","refsource":"SECTRACK","tags":["Third Party Advisory","VDB Entry"],"title":"Apple Safari Input Validation Bugs Let Remote Users Spoof the Address Bar and Conduct Cross-Site Scripting Attacks - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1039427","name":"1039427","refsource":"SECTRACK","tags":["Third Party Advisory","VDB Entry"],"title":"Apple macOS/OS X Multiple Flaws Let Remote and Local Users Bypass Security and Deny Service, Local Users Obtain Potentially Sensitive Information, and Applications Gain Elevated Privileges - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-7144","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-7144","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"7144","vulnerable":"1","versionEndIncluding":"10.3.3","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"iphone_os","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"7144","vulnerable":"1","versionEndIncluding":"10.1.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apple","cpe5":"safari","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"product-security@apple.com","ID":"CVE-2017-7144","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. The issue involves the \"WebKit\" component. It allows remote attackers to track Safari Private Browsing users by leveraging cookie mishandling."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"100991","refsource":"BID","url":"http://www.securityfocus.com/bid/100991"},{"name":"1039384","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1039384"},{"name":"1039427","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1039427"},{"name":"https://support.apple.com/HT208112","refsource":"CONFIRM","url":"https://support.apple.com/HT208112"},{"name":"https://support.apple.com/HT208116","refsource":"CONFIRM","url":"https://support.apple.com/HT208116"}]}},"nvd":{"publishedDate":"2017-10-23 01:29:00","lastModifiedDate":"2017-10-26 18:23:00","problem_types":["CWE-275"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":1.4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*","versionEndIncluding":"10.3.3","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*","versionEndIncluding":"10.1.2","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"7144","Ordinal":"103839","Title":"CVE-2017-7144","CVE":"CVE-2017-7144","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"7144","Ordinal":"1","NoteData":"An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. The issue involves the \"WebKit\" component. It allows remote attackers to track Safari Private Browsing users by leveraging cookie mishandling.","Type":"Description","Title":null},{"CveYear":"2017","CveId":"7144","Ordinal":"2","NoteData":"2017-10-22","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"7144","Ordinal":"3","NoteData":"2017-10-23","Type":"Other","Title":"Modified"}]}}}