First published: Thu Jul 20 2017(Updated: )
A DOMParser XSS issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mobile Safari | <10.1.2 | |
iStyle @cosme iPhone OS | <10.3.3 | |
tvOS | <10.2.2 | |
Apple WebKit |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7038 is classified as a medium severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
To mitigate CVE-2017-7038, users should update their affected Apple products to the latest software versions.
CVE-2017-7038 affects iOS versions before 10.3.3, Safari versions before 10.1.2, and tvOS versions before 10.2.2.
CVE-2017-7038 is a DOMParser XSS issue within the WebKit component of certain Apple products.
Yes, CVE-2017-7038 can be exploited remotely via malicious web content.