CVE-2017-2447
HIGHSafari < 10.1 - Memory Corruption via Crafted Web Site
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-2447. PoCs published by Google Security Research.
AI-analyzed exploit summary This exploit demonstrates an out-of-bounds read vulnerability in WebKit's handling of bound function arguments. By manipulating the Array prototype and altering the length of a bound function's arguments array, an attacker can trigger type confusion, potentially leading to arbitrary code execution.
Description
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to obtain sensitive information or cause a denial of service (memory corruption) via a crafted web site.
Exploits (1)
This exploit demonstrates an out-of-bounds read vulnerability in WebKit's handling of bound function arguments. By manipulating the Array prototype and altering the length of a bound function's arguments array, an attacker can trigger type confusion, potentially leading to arbitrary code execution.
References (7)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H