CVE-2015-3754 describes a privacy vulnerability in Apple Safari versions prior to 6.2.8, 7.1.8, and 8.0.8, where the private browsing mode failed to prevent the caching of HTTP authentication credentials. This flaw could allow remote attackers, via a specially crafted website, to track users by accessing these stored credentials. The vulnerability has a CVSS score of 4.3 (Medium), indicating a network-based attack with medium complexity and a potential impact on confidentiality. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.0, < 6.2.8CPE matchmatch criteria | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* | ||
>= 7.0, < 7.1.8CPE matchmatch criteria | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* | ||
>= 8.0, < 8.0.8CPE matchmatch criteria | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.