First published: Tue Sep 12 2017(Updated: )
An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. iTunes before 12.7 on Windows is affected. tvOS before 11 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive cookie information via a custom URL scheme.
Credit: Apple Apple Apple Apple product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iCloud for Windows | <7.0 | 7.0 |
Apple iTunes for Windows | <12.7 | 12.7 |
Apple tvOS | <11 | 11 |
Apple iOS | <11 | 11 |
Apple Safari | <=10.1.2 | |
Apple iPhone OS | <=10.3.3 | |
Apple tvOS | <=10.2.2 | |
Apple iCloud | <=6.9.1 | |
Apple iTunes | <=12.6.2 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2017-7090 is a vulnerability that allows remote attackers to bypass certain security features in Apple products.
iOS before version 11, Safari before version 11, iCloud before version 7.0 on Windows, and iTunes before version 12.7 on Windows.
CVE-2017-7090 has a severity level of 7.5 (High).
To fix CVE-2017-7090, it is recommended to update to the latest version of the affected Apple products.
More information about CVE-2017-7090 can be found on the Apple support website and security advisory websites like SecurityFocus and SecurityTracker.