CVE-2017-2364: Infoleak
WebKit. A validation issue existed in the handling of page loading. This issue was addressed through improved logic.
Other sources
WebKit. Multiple validation issues existed in the handling of page loading. This issue was addressed through improved logic.
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 10.3 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 10.2.1
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2017-2397
- CVE-2017-2430
- CVE-2017-2462
- CVE-2017-2379
- CVE-2017-2417
- CVE-2017-2444
- CVE-2017-2435
- CVE-2017-2450
- CVE-2017-2461
- CVE-2017-2414
- CVE-2017-2487
- CVE-2017-2406
- CVE-2017-2407
- CVE-2017-2439
- CVE-2017-2434
- CVE-2017-2428
- CVE-2017-2416
- CVE-2017-2432
- CVE-2017-2467
- CVE-2016-3619
- CVE-2017-2412
- CVE-2017-2491
- CVE-2017-2492
- CVE-2017-2398
- CVE-2017-2401
- CVE-2017-2440
- CVE-2017-2456
- CVE-2017-2472
- CVE-2017-2473
- CVE-2017-2474
- CVE-2017-2478
- CVE-2017-2482
- CVE-2017-2483
- CVE-2017-2490
- CVE-2017-2458
- CVE-2017-2448
- CVE-2017-2390
- CVE-2017-2441
- CVE-2017-5029
- CVE-2017-2399
- CVE-2017-2484
- CVE-2017-2380
- CVE-2017-2404
- CVE-2017-2376
- CVE-2017-2384
- CVE-2017-2389
- CVE-2017-2453
- CVE-2017-2393
- CVE-2017-2400
- CVE-2017-6976
- CVE-2017-2423
- CVE-2017-2451
- CVE-2017-2485
- CVE-2017-2452
- CVE-2017-2378
- CVE-2017-2486
- CVE-2017-2386
- CVE-2017-2394
- CVE-2017-2396
- CVE-2016-9642
- CVE-2017-2395
- CVE-2017-2454
- CVE-2017-2455
- CVE-2017-2457
- CVE-2017-2459
- CVE-2017-2460
- CVE-2017-2464
- CVE-2017-2465
- CVE-2017-2466
- CVE-2017-2468
- CVE-2017-2469
- CVE-2017-2470
- CVE-2017-2476
- CVE-2017-2481
- CVE-2017-2415
- CVE-2017-2419
- CVE-2016-9643
- CVE-2017-2424
- CVE-2017-2433
- CVE-2017-2364
- CVE-2017-2367
- CVE-2017-2445
- CVE-2017-2446
- CVE-2017-2447
- CVE-2017-2463
- CVE-2017-2471
- CVE-2017-2475
- CVE-2017-2479
- CVE-2017-2480
- CVE-2017-2493
- CVE-2017-2442
- CVE-2017-2377
- CVE-2017-2405
- CVE-2017-2383
- CVE-2017-2375
- CVE-2017-2368
- CVE-2017-2370
- CVE-2017-2360
- CVE-2016-8687
- CVE-2017-2352
- CVE-2017-2350
- CVE-2017-2354
- CVE-2017-2362
- CVE-2017-2373
- CVE-2017-2355
- CVE-2017-2356
- CVE-2017-2369
- CVE-2017-2366
- CVE-2017-2363
- CVE-2017-2371
- CVE-2017-2365
- CVE-2017-2351
Frequently Asked Questions
What is the severity of CVE-2017-2364?
CVE-2017-2364 has been rated with high severity due to the potential for exploitation in WebKit, affecting user security.
How do I fix CVE-2017-2364?
To fix CVE-2017-2364, update your Apple device to the latest iOS version or Safari version, specifically versions 10.3 or 10.2.1 respectively.
Which Apple products are affected by CVE-2017-2364?
CVE-2017-2364 affects Apple iOS versions up to 10.2.0 and Safari versions up to 10.0.2.
What type of issue does CVE-2017-2364 represent?
CVE-2017-2364 represents a validation issue related to the handling of page loading within WebKit.
Is CVE-2017-2364 exploitable in the wild?
There have been indications that CVE-2017-2364 could be exploited in the wild, prompting swift software updates.