CVE-2017-2442
MEDIUMSafari < 10.1 - Same Origin Policy Bypass via WebKit JavaScript Bindings
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-2442. PoCs published by Google Security Research.
AI-analyzed exploit summary This PoC exploits a type confusion vulnerability in WebKit's JSCallbackData, allowing cross-origin JavaScript execution by manipulating the global object context during callback invocation. The exploit uses an iframe to trigger the vulnerability and execute arbitrary code in a different origin's context.
Description
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "WebKit JavaScript Bindings" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.
Exploits (1)
This PoC exploits a type confusion vulnerability in WebKit's JSCallbackData, allowing cross-origin JavaScript execution by manipulating the global object context during callback invocation. The exploit uses an iframe to trigger the vulnerability and execute arbitrary code in a different origin's context.
References (6)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N