First published: Mon Jan 23 2017(Updated: )
WebKit. A validation issue existed in the handling of page loading. This issue was addressed through improved logic.
Credit: lokihardt Google Project Zerolokihardt Google Project Zerolokihardt Google Project Zero product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS, iPadOS, and watchOS | <10.2.1 | 10.2.1 |
Apple iOS, iPadOS, and watchOS | <10.3 | 10.3 |
iStyle @cosme iPhone OS | <=10.2.0 | |
Apple Mobile Safari | <=10.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2017-2364 has been rated with high severity due to the potential for exploitation in WebKit, affecting user security.
To fix CVE-2017-2364, update your Apple device to the latest iOS version or Safari version, specifically versions 10.3 or 10.2.1 respectively.
CVE-2017-2364 affects Apple iOS versions up to 10.2.0 and Safari versions up to 10.0.2.
CVE-2017-2364 represents a validation issue related to the handling of page loading within WebKit.
There have been indications that CVE-2017-2364 could be exploited in the wild, prompting swift software updates.