Exploitation Summary
EIP tracks 1 public exploit for CVE-2017-2371. PoCs published by Google Security Research.
AI-analyzed exploit summary This exploit leverages a logic flaw in Safari's popup blocker by manipulating frame navigation checks, allowing popups to bypass user interaction requirements. It uses either sandboxed or cross-origin iframes to trigger the vulnerability.
Description
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. The issue involves the "WebKit" component, which allows remote attackers to launch popups via a crafted web site.
Exploits (1)
This exploit leverages a logic flaw in Safari's popup blocker by manipulating frame navigation checks, allowing popups to bypass user interaction requirements. It uses either sandboxed or cross-origin iframes to trigger the vulnerability.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N