First published: Sun Apr 02 2017(Updated: )
An issue was discovered in certain Apple products. Safari before 10.1 is affected. The issue involves the "Safari Login AutoFill" component. It allows local users to obtain access to locked keychain items via unspecified vectors.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mobile Safari | <=10.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-2385 is classified as a medium-severity vulnerability due to its potential to allow local users access to sensitive data.
To fix CVE-2017-2385, update Safari to version 10.1 or later.
CVE-2017-2385 affects users of Safari versions prior to 10.1.
CVE-2017-2385 involves the "Safari Login AutoFill" component.
CVE-2017-2385 allows local users to gain access to locked keychain items.