CVE-2017-7064
MEDIUMApple <10.3.3, <10.1.2, <6.2.2, <12.6.2 - Info Disclosure
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-7064. PoCs published by Google Security Research.
AI-analyzed exploit summary This PoC exploits a memory corruption vulnerability in WebKit's JSC (CVE-2017-7064) where uninitialized memory from an 'ArrayWithUndecided' type array is copied into another array during concatenation, potentially leading to information leakage or further exploitation.
Description
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. The issue involves the "WebKit" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.
Exploits (1)
This PoC exploits a memory corruption vulnerability in WebKit's JSC (CVE-2017-7064) where uninitialized memory from an 'ArrayWithUndecided' type array is copied into another array during concatenation, potentially leading to information leakage or further exploitation.
References (7)
Scores
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N