First published: Mon May 22 2017(Updated: )
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mobile Safari | <=10.1 | |
iStyle @cosme iPhone OS | <=10.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-2538 is considered to be a critical vulnerability as it allows remote attackers to execute arbitrary code on affected devices.
To fix CVE-2017-2538, update your Apple iOS to version 10.3.2 or later and Safari to version 10.1.1 or later.
CVE-2017-2538 affects iOS versions earlier than 10.3.2 and Safari versions earlier than 10.1.1.
CVE-2017-2538 allows remote attackers to execute arbitrary code or cause a denial of service through memory corruption.
CVE-2017-2538 involves the WebKit component in affected Apple products.