CVE-2016-7152: Apple Safari

Medium severity, CVSS 5.3. EPSS: 14% chance of exploitation in the next 30 days.

The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.

Affected products

  • Apple Safari: any version
  • Google Chrome: affected versions not specified
  • Microsoft Edge: affected versions not specified
  • Microsoft Internet Explorer: affected versions not specified
  • Mozilla Firefox: any version
  • Opera Opera: affected versions not specified

Published 2016-09-06. Last modified 2026-06-17.