CVE-2017-2371: Input Validation
WebKit. An issue existed in the handling of blocking popups. This was addressed through improved input validation.
Other sources
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. The issue involves the "WebKit" component, which allows remote attackers to launch popups via a crafted web site.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 10.2.1
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2017-2371?
CVE-2017-2371 has a medium severity level due to its potential to be exploited by remote attackers.
Who is affected by CVE-2017-2371?
CVE-2017-2371 affects Apple iOS versions prior to 10.2.1.
How do I fix CVE-2017-2371?
To fix CVE-2017-2371, upgrade your iOS device to version 10.2.1 or later.
What component is involved in CVE-2017-2371?
CVE-2017-2371 involves the WebKit component which handles web content in Apple devices.
What type of attack does CVE-2017-2371 allow?
CVE-2017-2371 allows remote attackers to launch blocking popups through crafted web content.