First published: Mon May 22 2017(Updated: )
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mobile Safari | <=10.1 | |
iStyle @cosme iPhone OS | <=10.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-2539 has a high severity rating due to its potential for remote code execution and denial of service.
To fix CVE-2017-2539, update your iOS device to version 10.3.2 or higher and update Safari to version 10.1.1 or higher.
CVE-2017-2539 affects iOS versions prior to 10.3.2 and Safari versions prior to 10.1.1.
Yes, CVE-2017-2539 can be exploited remotely by attackers through specially crafted web content.
CVE-2017-2539 involves the WebKit component used in Apple's Safari and iOS.