First published: Thu Jul 20 2017(Updated: )
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. The issue involves the "WebKit" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iTunes for Windows | <=12.6.1 | |
Microsoft Windows | ||
Apple Mobile Safari | <=10.1.1 | |
iOS | <=10.3.2 | |
Apple iCloud for Windows | <=6.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7064 has been rated as having a high severity due to the potential for attackers to bypass memory-read restrictions.
To fix CVE-2017-7064, users should update affected Apple software, including iOS, Safari, iCloud, and iTunes to their latest versions.
CVE-2017-7064 affects iOS versions prior to 10.3.3, Safari versions prior to 10.1.2, iCloud for Windows before 6.2.2, and iTunes before 12.6.2.
Yes, CVE-2017-7064 can potentially be exploited remotely, allowing attackers to gain access through vulnerable WebKit components.
CVE-2017-7064 involves the WebKit component, which is integral to rendering web content in Apple software.