CVE-2017-7089

MEDIUM

Apple <11 - XSS

Title source: llm

Description

An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that is mishandled during parent-tab processing.

Exploits (3)

exploitdb WORKING POC
by Anton Lopanitsyn · htmllocalmultiple
https://www.exploit-db.com/exploits/45866
nomisec WORKING POC 63 stars
by Bo0oM · poc
https://github.com/Bo0oM/CVE-2017-7089
nomisec STUB 1 stars
by aymankhalfatni · poc
https://github.com/aymankhalfatni/Safari_Mac

Scores

CVSS v3 6.1
EPSS 0.0446
EPSS Percentile 89.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (5)
apple/icloud < 6.9.1
apple/iphone_os < 10.3.3
apple/itunes < 12.6.2
apple/safari < 10.1.2
apple/tvos < 10.2.2
Published Oct 23, 2017
Tracked Since Feb 18, 2026