First published: Mon Mar 27 2017(Updated: )
WebKit. Multiple memory corruption issues were addressed through improved input validation.
Credit: Apple Apple Gustavo Grieco product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS | <10.3 | 10.3 |
Apple Safari | <=10.0.3 | |
Apple iPhone OS | <=10.2.1 | |
Apple tvOS | <=10.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2017-2394 is classified as a high severity vulnerability due to the potential for remote code execution.
To fix CVE-2017-2394, update affected Apple products to the latest versions: iOS 10.3, Safari 10.1, and tvOS 10.2.
CVE-2017-2394 affects iOS versions before 10.3, Safari versions before 10.1, tvOS versions before 10.2, and iPhone OS versions before 10.2.1.
Yes, CVE-2017-2394 can be exploited remotely, allowing attackers to execute arbitrary code on the affected device.
The vulnerability involves the WebKit component, which is the underlying engine for Safari and other Apple browsers.