First published: Mon Mar 27 2017(Updated: )
WebKit. A logic issue existed in the handling of frame objects. This issue was addressed with improved state management.
Credit: lokihardt Google Project Zero product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS | <10.3 | 10.3 |
Apple Safari | <=10.0.3 | |
Apple iPhone OS | <=10.2.1 | |
tvOS | <=10.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2017-2445 has a moderate severity, as it affects multiple Apple products and can lead to unexpected behavior.
To fix CVE-2017-2445, update affected devices to the latest versions of iOS, Safari, or tvOS.
CVE-2017-2445 affects iOS prior to 10.3, Safari prior to 10.1, and tvOS prior to 10.2.
CVE-2017-2445 is a logic issue related to the handling of frame objects in WebKit.
There are no known workarounds for CVE-2017-2445 besides updating to the patched versions.