The CFNetwork HTTPProtocol component in Apple iOS before 9 and OS X before 10.11 does not properly recognize the HSTS preload list during a Safari private-browsing session, which makes it easier for remote attackers to obtain sensitive information by sniffing the network.
| Software | From | Fixed in |
|---|---|---|
| apple / mac_os_x | - | 10.10.4.x |
| apple / iphone_os | - | 8.4.1.x |