First published: Thu Jul 20 2017(Updated: )
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to spoof the address bar via a crafted web site that uses FRAME elements.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mobile Safari | <=10.1.1 | |
iStyle @cosme iPhone OS | <=10.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7011 is considered a medium severity vulnerability due to the potential for remote attacks to spoof the address bar.
To mitigate CVE-2017-7011, update Apple Safari to version 10.1.2 or later and ensure iOS is updated to 10.3.3 or later.
CVE-2017-7011 affects Apple Safari versions up to 10.1.1 and iOS versions up to 10.3.2.
CVE-2017-7011 involves the WebKit component, which is utilized in rendering web content.
Yes, CVE-2017-7011 can be exploited remotely via crafted websites that use FRAME elements.