First published: Mon May 22 2017(Updated: )
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. iCloud before 6.2.1 on Windows is affected. tvOS before 10.2.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
apple icloud windows | <=6.2 | |
Apple Safari | <=10.1 | |
Apple iPhone OS | <=10.3.1 | |
tvOS | <=10.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-2530 has been classified as a high severity vulnerability due to its potential to allow remote code execution.
To mitigate CVE-2017-2530, users should update their affected Apple products to the latest available versions, specifically iOS 10.3.2, Safari 10.1.1, iCloud 6.2.1 for Windows, and tvOS 10.2.1.
CVE-2017-2530 affects iOS versions prior to 10.3.2, Safari versions before 10.1.1, iCloud versions before 6.2.1 on Windows, and tvOS versions before 10.2.1.
CVE-2017-2530 involves the "WebKit" component of Apple products.
Yes, exploitation of CVE-2017-2530 could allow attackers to execute arbitrary code, potentially leading to data breaches.