First published: Mon May 22 2017(Updated: )
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
iStyle @cosme iPhone OS | <=10.3.1 | |
Apple Mobile Safari | <=10.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-2496 is considered a high severity vulnerability due to its ability to allow remote code execution.
CVE-2017-2496 affects the WebKit component in iOS versions before 10.3.2 and Safari versions before 10.1.1.
To fix CVE-2017-2496, you should update your iOS device to version 10.3.2 or later and Safari to version 10.1.1 or later.
CVE-2017-2496 can be exploited through crafted web content that leads to arbitrary code execution or denial of service.
Apple iPhones and iPads running iOS versions before 10.3.2 are likely vulnerable to CVE-2017-2496.