VYPR
Unrated severityNVD Advisory· Published Jun 22, 2010· Updated Apr 29, 2026

CVE-2010-1755

CVE-2010-1755

Description

Safari in Apple iOS before 4 on the iPhone and iPod touch does not properly implement the Accept Cookies preference, which makes it easier for remote web servers to track users via a cookie.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Safari in iOS before 4 ignores the Accept Cookies preference, allowing remote servers to track users via cookies without consent.

Vulnerability

Safari in Apple iOS before version 4 on iPhone and iPod touch does not properly implement the Accept Cookies preference [1]. This means that even if a user has configured Safari to reject cookies, the browser still accepts cookies from remote web servers. The bug affects all devices running iOS versions prior to 4 [1].

Exploitation

An attacker can host a malicious website that sets a tracking cookie when visited by an iOS user running a vulnerable version of Safari. No special network position or authentication is required; the attacker simply relies on the user visiting the website via Safari. The cookie is stored and sent back to the attacker's server on subsequent requests, enabling user tracking despite the user's cookie-blocking preference [1].

Impact

Successful exploitation allows a remote web server to place cookies on an iOS device and track the user's browsing activity across sessions. This defeats the user's explicit cookie-blocking setting, leading to a privacy breach and unauthorized information disclosure about the user's browsing habits [1].

Mitigation

The vulnerability is fixed in iOS 4, released on June 21, 2010 [1]. Users should update to iOS 4 or later via iTunes on a computer. No workaround is available; the only mitigation is to install the update. The referenced advisory [1] is archived but confirms the fix.

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.