CVE-2016-7153: Apple Safari
Medium severity, CVSS 5.3. EPSS: 14% chance of exploitation in the next 30 days.
The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.
Affected products
- Apple Safari: any version
- Google Chrome: affected versions not specified
- Microsoft Edge: affected versions not specified
- Microsoft Internet Explorer: affected versions not specified
- Mozilla Firefox: any version
- Opera Opera Browser: affected versions not specified
Published 2016-09-06. Last modified 2026-06-17.