First published: Mon May 22 2017(Updated: )
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
iStyle @cosme iPhone OS | <=10.3.1 | |
Apple Mobile Safari | <=10.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-2514 is classified as a high severity vulnerability due to its potential to allow remote code execution.
To fix CVE-2017-2514, update affected Apple products to iOS version 10.3.2 or later and Safari version 10.1.1 or later.
CVE-2017-2514 affects Apple iPhone OS versions up to 10.3.1 and Safari versions up to 10.1.
CVE-2017-2514 enables attackers to execute arbitrary code or cause a denial of service through a crafted web content.
Yes, CVE-2017-2514 remains a concern for users who have not updated their affected devices to the patched versions.