Cookie Modification Vulnerability in Android Browser
CVE-2008-7298

Currently unrated

Key Information:

Vendor

Google

Vendor
CVE Published:
9 August 2011

What is CVE-2008-7298?

The Android browser lacks adequate restrictions on cookie modifications within HTTPS sessions. This insufficiency allows man-in-the-middle attackers to overwrite or delete cookies using a Set-Cookie header in HTTP responses. The vulnerability stems from missing implementation of the HTTP Strict Transport Security (HSTS) feature to include subdomains, leading to potential unauthorized cookie changes during user sessions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.