First published: Mon May 22 2017(Updated: )
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mobile Safari | <=10.1 | |
iStyle @cosme iPhone OS | <=10.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-2526 is rated as critical due to its potential to allow remote code execution or denial of service.
To mitigate CVE-2017-2526, update to iOS version 10.3.2 or later and Safari version 10.1.1 or later.
CVE-2017-2526 affects certain Apple products, specifically iOS devices running versions prior to 10.3.2 and Safari versions before 10.1.1.
The vulnerability CVE-2017-2526 involves the WebKit component within affected Apple products.
CVE-2017-2526 allows remote attackers to execute arbitrary code or cause a denial of service through crafted web content.