First published: Mon May 22 2017(Updated: )
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that improperly interacts with container nodes.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mobile Safari | <=10.1 | |
iStyle @cosme iPhone OS | <=10.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-2508 is classified as a high severity vulnerability due to the potential for remote Universal XSS attacks.
To fix CVE-2017-2508, you should update your iOS device to version 10.3.2 or later and Safari to version 10.1.1 or later.
CVE-2017-2508 affects iOS versions before 10.3.2 and Safari versions prior to 10.1.1.
CVE-2017-2508 allows attackers to conduct Universal XSS (UXSS) attacks through maliciously crafted web pages.
To mitigate risks from CVE-2017-2508, ensure that your software is updated regularly and avoid visiting untrusted websites.