Unrated severityNVD Advisory· Published Aug 9, 2011· Updated Apr 29, 2026
CVE-2008-7298
CVE-2008-7298
Description
The Android browser in Android cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attackers to overwrite or delete arbitrary cookies via a Set-Cookie header in an HTTP response, related to lack of the HTTP Strict Transport Security (HSTS) includeSubDomains feature, aka a "cookie forcing" issue.
Affected products
2- cpe:2.3:a:android:android_browser:*:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- bugzilla.mozilla.org/show_bug.cginvdPatch
- code.google.com/p/browsersec/wiki/Part2nvd
- michael-coates.blogspot.com/2010/01/cookie-forcing-trust-your-cookies-no.htmlnvd
- scarybeastsecurity.blogspot.com/2008/11/cookie-forcing.htmlnvd
- scarybeastsecurity.blogspot.com/2011/02/some-less-obvious-benefits-of-hsts.htmlnvd
News mentions
0No linked articles in our index yet.