CVE-2012-3748

Safari < 6.0.1 - Remote Code Execution via JavaScript Array Race Condition

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2012-3748. PoCs published by Vitaliy Toropov.

AI-analyzed exploit summary This advisory describes a heap buffer overflow vulnerability in Apple Safari's WebKit JavaScriptCore JSArray::sort method, which can lead to memory corruption and arbitrary code execution. The exploit details are referenced but not directly included in the provided text.

Description

Race condition in WebKit in Apple iOS before 6.0.1 and Safari before 6.0.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving JavaScript arrays.

Exploits (1)

exploitdb WRITEUP
by Vitaliy Toropov · textremoteios
https://www.exploit-db.com/exploits/28081

This advisory describes a heap buffer overflow vulnerability in Apple Safari's WebKit JavaScriptCore JSArray::sort method, which can lead to memory corruption and arbitrary code execution. The exploit details are referenced but not directly included in the provided text.

Classification
Writeup 100%
Attack Type
Rce
Complexity
Complex
Reliability
Theoretical
Target: Apple Safari 6.0.1 for iOS 6.0 and OS X 10.7/8
No auth needed
Prerequisites: Target must be running a vulnerable version of Apple Safari
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (11)

Core 11
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/51445
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT5567
Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2013/Sep/msg00003.html
Vendor Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2012/Nov/msg00000.html
Vendor Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2012/Nov/msg00001.html
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT5921
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/56362
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT5568
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2012-11/0012.html
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2012-11/0013.html
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT5598

Scores

EPSS 0.1442
EPSS Percentile 96.2%

Details

CWE
CWE-362
Status published
Products (49)
apple/iphone_os 1.0.0
apple/iphone_os 1.0.1
apple/iphone_os 1.0.2
apple/iphone_os 1.1.0
apple/iphone_os 1.1.1
apple/iphone_os 1.1.2
apple/iphone_os 1.1.3
apple/iphone_os 1.1.4
apple/iphone_os 1.1.5
apple/iphone_os 2.0
... and 39 more
Published Nov 03, 2012
Tracked Since Feb 18, 2026