First published: Tue Sep 19 2017(Updated: )
Location Framework. A permissions issue existed in the handling of the location variable. This was addressed with additional ownership checks.
Credit: Igor Makarov MoovitWill McGinty Shawnna Rodriguez Bottle Rocket Studios product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPhone OS | =10.3.3 | |
Apple iOS | <11 | 11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2017-7148 is a vulnerability in the Location Framework component of certain Apple products, allowing attackers to obtain sensitive location information via a crafted app.
iOS versions before 11 are affected by CVE-2017-7148.
An attacker can exploit CVE-2017-7148 by creating a malicious app that reads the location variable and gathers sensitive location information.
CVE-2017-7148 has a severity level of medium, with a severity value of 3.3.
To fix CVE-2017-7148, it is recommended to update to iOS version 11 or later, as this vulnerability is fixed in iOS 11.