First published: Mon Mar 27 2017(Updated: )
WebKit. A logic issue existed in frame handling. This issue was addressed through improved state management.
Credit: lokihardt Google Project Zero product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS, iPadOS, and watchOS | <10.3 | 10.3 |
Apple Mobile Safari | <10.1 | |
iStyle @cosme iPhone OS | <10.3 | |
tvOS | <10.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2017-2475 is classified as a high-severity vulnerability affecting various Apple products due to a logic issue in frame handling.
To mitigate CVE-2017-2475, users should update their devices to the latest available versions of iOS, Safari, or tvOS as indicated by Apple.
CVE-2017-2475 affects Apple iOS versions before 10.3, Safari versions before 10.1, and tvOS versions before 10.2.
CVE-2017-2475 is a logic vulnerability related to frame handling within the WebKit component.
Yes, iOS versions prior to 10.3 are vulnerable to CVE-2017-2475 and should be updated immediately.