CVE-2016-7153: Apple Safari

Medium severity, CVSS 5.3. EPSS: 14% chance of exploitation in the next 30 days.

The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.

Affected products

  • Apple Safari: any version
  • Google Chrome: affected versions not specified
  • Microsoft Edge: affected versions not specified
  • Microsoft Internet Explorer: affected versions not specified
  • Mozilla Firefox: any version
  • Opera Opera Browser: affected versions not specified

Published 2016-09-06. Last modified 2026-06-17.