First published: Mon Jan 23 2017(Updated: )
WebKit. Multiple memory corruption issues were addressed through improved memory handling.
Credit: product-security@apple.com Neymar TencentIvan Fratric Google Project Zero
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS, iPadOS, and watchOS | <10.2.1 | 10.2.1 |
iStyle @cosme iPhone OS | <10.2.1 | |
Apple Mobile Safari | <10.0.3 | |
Apple iCloud for Windows | <6.1.1 | |
Apple iTunes for Windows | <12.5.5 | |
tvOS | <10.1.1 | |
WebKitGTK+ | <2.16.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2017-2354 has been classified with a high severity rating due to the potential for memory corruption issues.
To fix CVE-2017-2354, users should update their affected Apple products to the latest versions which address the memory corruption vulnerabilities.
CVE-2017-2354 affects Apple iOS versions prior to 10.2.1, Safari versions before 10.0.3, and iCloud versions before 6.1.1 among others.
There is no specific information confirming that CVE-2017-2354 is actively exploited in the wild, but it is advisable to apply updates due to its severity.
CVE-2017-2354 was disclosed in January 2017 as part of a series of updates addressing memory corruption vulnerabilities in WebKit.