CVE-2017-7064
MEDIUMApple <10.3.3, <10.1.2, <6.2.2, <12.6.2 - Info Disclosure
Title source: llmDescription
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. The issue involves the "WebKit" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Google Security Research · htmldosmultiple
https://www.exploit-db.com/exploits/42375
References (7)
Scores
CVSS v3
5.5
EPSS
0.0332
EPSS Percentile
87.2%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Details
CWE
CWE-20
Status
published
Products (5)
n/a/n/a
apple/itunes
< 12.6.1
apple/safari
< 10.1.1
apple/iphone_os
< 10.3.2
apple/icloud
< 6.2.1
Published
Jul 20, 2017
Tracked Since
Feb 18, 2026