CVE-2017-2367
MEDIUMSafari < 10.1 - Same Origin Policy Bypass via WebKit
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-2367. PoCs published by Google Security Research.
AI-analyzed exploit summary This PoC exploits a vulnerability in Safari where a frame is not properly detached from an unloaded window, allowing access to the new document's named properties. It demonstrates a cross-origin access issue by injecting a script into a node retrieved from a different domain.
Description
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.
Exploits (1)
This PoC exploits a vulnerability in Safari where a frame is not properly detached from an unloaded window, allowing access to the new document's named properties. It demonstrates a cross-origin access issue by injecting a script into a node retrieved from a different domain.
References (7)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N