First published: Wed Mar 26 2014(Updated: )
Heap-based buffer overflow in Apple Safari 7.0.2 allows remote attackers to execute arbitrary code and bypass a sandbox protection mechanism via unspecified vectors, as demonstrated by Liang Chen during a Pwn2Own competition at CanSecWest 2014.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mobile Safari | =7.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-1303 is considered critical due to its potential for remote code execution and sandbox bypass.
To fix CVE-2014-1303, update Apple Safari to the latest version available.
Exploiting CVE-2014-1303 can allow attackers to execute arbitrary code on the affected system.
CVE-2014-1303 specifically affects Apple Safari version 7.0.2.
You can determine vulnerability to CVE-2014-1303 by checking if you are running Apple Safari version 7.0.2.