CVE-2014-1296: Apple iPhone OS

Medium severity, CVSS 4.3. EPSS: 1.9% chance of exploitation in the next 30 days.

CFNetwork in Apple iOS before 7.1.1, Apple OS X through 10.9.2, and Apple TV before 6.1.1 does not ensure that a Set-Cookie HTTP header is complete before interpreting the header's value, which allows remote attackers to bypass intended access restrictions by triggering the closing of a TCP connection during transmission of a header, as demonstrated by an HTTPOnly restriction.

Affected products

  • Apple iPhone OS: up to and including 7.1; version 7.0 only; version 7.0.1 only; version 7.0.2 only; version 7.0.3 only; version 7.0.4 only; …
  • Apple Mac OS X: version 10.8.0 only; version 10.8.1 only; version 10.8.2 only; version 10.8.3 only; version 10.8.4 only; version 10.8.5 only; …
  • Apple Mac OS X Server: version 10.7.0 only; version 10.7.1 only; version 10.7.2 only; version 10.7.3 only; version 10.7.4 only; version 10.7.5 only
  • Apple tvOS: up to and including 6.1; version 6.0 only; version 6.0.1 only; version 6.0.2 only

Published 2014-04-23. Last modified 2026-06-17.