logo

Apple Patches Persistent Cookie Vulnerability Discovered by Zscaler

ID: 3de045b4-b681-5db1-b3db-e4ef62af2b80

STIX ID: report--3de045b4-b681-5db1-b3db-e4ef62af2b80

Feed Name: Zscaler Security Research Blog

Threat Score
55/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler reported a vulnerability in macOS El Capitan that permitted unprivileged applications to read Safari's persistent cookies, which could allow attackers to impersonate users and access account data (including webmail). Apple mitigated the issue in Security Update 2016-004 for OS X 10.11.6; the advisory also provides background on persistent cookie usage across websites.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.