CVE-2017-2453
MEDIUMApple Safari < 10.0.3 - Improper Input Validation
Title source: ruleDescription
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof FaceTime prompts in the user interface via a crafted web site.
Scores
CVSS v3
6.5
EPSS
0.0037
EPSS Percentile
58.3%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Classification
CWE
CWE-20
Status
published
Affected Products (3)
apple/safari
< 10.0.3
apple/iphone_os
< 10.2.1
n/a/n/a
Timeline
Published
Apr 02, 2017
Tracked Since
Feb 18, 2026