First published: Mon May 22 2017(Updated: )
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS before 10.2.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Safari | <=10.1 | |
Apple iPhone OS | <=10.3.1 | |
tvOS | <=10.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-6980 has been rated as a high-severity vulnerability due to its potential for remote code execution.
To fix CVE-2017-6980, update Safari to version 10.1.1 or later, and update any affected Apple devices to their latest iOS or tvOS version.
CVE-2017-6980 affects iOS versions before 10.3.2, Safari versions before 10.1.1, and tvOS versions before 10.2.1.
Yes, CVE-2017-6980 can lead to data breaches by allowing attackers to execute arbitrary code on the affected devices.
The vulnerability CVE-2017-6980 involves the 'WebKit' component used in Apple's web browsing software.