First published: Mon May 22 2017(Updated: )
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mobile Safari | <=10.1 | |
iStyle @cosme iPhone OS | <=10.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-2506 has a high severity rating due to its potential to allow remote code execution.
To fix CVE-2017-2506, update your iOS device to version 10.3.2 or later and ensure Safari is updated to version 10.1.1 or later.
CVE-2017-2506 affects iOS versions before 10.3.2 and Safari versions before 10.1.1 on Apple devices.
CVE-2017-2506 is a memory corruption vulnerability in the WebKit component that can lead to denial of service or arbitrary code execution.
Yes, CVE-2017-2506 can be exploited remotely by attackers through crafted web content.