Unrated severityNVD Advisory· Published Feb 27, 2014· Updated Jun 17, 2026
CVE-2014-1257
CVE-2014-1257
Description
CFNetwork in Apple OS X through 10.8.5 does not remove session cookies upon a Safari reset action, which allows physically proximate attackers to bypass intended access restrictions by leveraging an unattended workstation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8- Range: <=10.8.5
cpe:2.3:o:apple:mac_os_x:*:supplemental_update:*:*:*:*:*:*+ 6 more
- cpe:2.3:o:apple:mac_os_x:*:supplemental_update:*:*:*:*:*:*range: <=10.8.5
- cpe:2.3:o:apple:mac_os_x:10.8.0:*:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x:10.8.1:*:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x:10.8.2:*:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x:10.8.3:*:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x:10.8.4:*:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x:10.8.5:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- support.apple.com/kb/HT6150nvdVendor Advisory
News mentions
0No linked articles in our index yet.