First published: Mon Feb 20 2017(Updated: )
An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
iPhone OS | <=10.1.1 | |
Safari | <=10.0.1 | |
iCloud | <=6.0.1 | |
iTunes | <=12.5.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-7649 has a high severity rating due to its potential to allow remote code execution.
CVE-2016-7649 affects iOS versions before 10.2, Safari versions before 10.0.2, iCloud versions before 6.1, and iTunes versions before 12.5.4.
To fix CVE-2016-7649, update affected Apple products to their latest versions.
Yes, CVE-2016-7649 can be exploited remotely allowing attackers to execute arbitrary code.
CVE-2016-7649 involves the WebKit component of affected Apple products.