First published: Thu Jul 20 2017(Updated: )
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iCloud for Windows | <6.2.2 | |
Apple iTunes for Windows | <12.6.2 | |
Microsoft Windows | ||
Apple WebKit | ||
Apple Mobile Safari | <10.1.2 | |
iStyle @cosme iPhone OS | <10.3.3 | |
tvOS | <10.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7041 is classified with a high severity level due to its ability to allow remote attackers to execute arbitrary code.
To fix CVE-2017-7041, update your affected Apple products to the latest versions that are not vulnerable.
CVE-2017-7041 affects iOS before version 10.3.3, Safari before version 10.1.2, iCloud for Windows before version 6.2.2, iTunes for Windows before version 12.6.2, and tvOS before version 10.2.2.
The vulnerable component in CVE-2017-7041 is the WebKit component used in various Apple products.
Yes, CVE-2017-7041 can be exploited remotely without physical access to the vulnerable device.