First published: Mon Mar 27 2017(Updated: )
CoreText. An out-of-bounds read was addressed through improved input validation.
Credit: John Villamil Doyensec product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS | <10.3 | 10.3 |
Apple iPhone OS | <=10.2.1 | |
macOS Yosemite | <=10.12.3 | |
tvOS | <=10.1.1 | |
watchOS | <=3.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2017-2450 has a high severity rating due to the potential for exploitation through out-of-bounds read vulnerabilities.
To fix CVE-2017-2450, update your affected Apple devices to at least iOS 10.3, macOS 10.12.4, tvOS 10.2, or watchOS 3.2.
CVE-2017-2450 affects iOS devices before version 10.3, macOS before version 10.12.4, tvOS before version 10.2, and watchOS before version 3.2.
CVE-2017-2450 is classified as an out-of-bounds read vulnerability within the CoreText component.
No specific workaround is available for CVE-2017-2450; updating to the latest software version is recommended.