Search/CVE-2015-7023
CVE

CVE-2015-7023

CFNetwork in Apple iOS before 9.1 and OS X before 10.11.1 does not properly consider the uppercase-versus-lowercase distinction during cookie parsing, which allows remote web servers to overwrite cookies via unspecified vectors.

CVSS v3.1
EPSS
1.63%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
Connections
3 relationships
Timeline
disclosure → media coverage
Oct 23, 2015
Disclosure — published as a CVE record. · last revised by NVD May 6, 2026