CVE-2017-7064

MEDIUM

Apple <10.3.3, <10.1.2, <6.2.2, <12.6.2 - Info Disclosure

Title source: llm

Description

An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. The issue involves the "WebKit" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Google Security Research · htmldosmultiple
https://www.exploit-db.com/exploits/42375

Scores

CVSS v3 5.5
EPSS 0.0332
EPSS Percentile 87.2%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Details

CWE
CWE-20
Status published
Products (5)
n/a/n/a
apple/itunes < 12.6.1
apple/safari < 10.1.1
apple/iphone_os < 10.3.2
apple/icloud < 6.2.1
Published Jul 20, 2017
Tracked Since Feb 18, 2026