[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248364

 
 

909

 
 

195388

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CCE
view XML

CCE-50336-7

Platform: cpe:/o:apple:mac_os_14Date: (C)2024-01-24   (M)2024-01-24



There is a vast network of groups that collect, use and sell user data. One method used to collect user data is pay and provide contented and services for website owners, along with that "assistance" the site owners push tracking cookies on visitors. In many cases the help allows a content owner to keep the site up. The tracking cookies allow information brokers to track web users across visited sites. For better privacy and to provide some resistance to data brokers prevent cross-tracking. Rationale:Cross-tracking allows data-brokers to follow you across the Internet to enable their business model of selling personal data. Users should protect their data and not volunteer it to marketing companies. Impact:Marketing companies will be unable to target you as effectively. Remediation: Profile Method: Create or edit a configuration profile with the following information: 1. The PayloadType string is com.apple.Safari 2. The key to include is BlockStoragePolicy 3. The key must be set to: 2 4. The key to also include is WebKitPreferences.storageBlockingPolicy 5. The key must be set to: 1 6. The key to also include is WebKitStorageBlockingPolicy 7. The key must be set to: 1


Parameter:

[Yes/No]


Technical Mechanism:

Remediation: Profile Method: Create or edit a configuration profile with the following information: 1. The PayloadType string is com.apple.Safari 2. The key to include is BlockStoragePolicy 3. The key must be set to: 2 4. The key to also include is WebKitPreferences.storageBlockingPolicy 5. The key must be set to: 1 6. The key to also include is WebKitStorageBlockingPolicy 7. The key must be set to: 1

CCSS Severity:CCSS Metrics:
CCSS Score : 4.3Attack Vector: NETWORK
Exploit Score: 2.8Attack Complexity: LOW
Impact Score: 1.4Privileges Required: NONE
Severity: MEDIUMUser Interaction: REQUIRED
Vector: AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:NScope: UNCHANGED
 Confidentiality: LOW
 Integrity: NONE
 Availability: NONE
  

References:
Resource IdReference
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:97024


OVAL    1
oval:org.secpod.oval:def:97024

© SecPod Technologies