CVE-2017-7152

MEDIUM

iPhone OS < 11.2 - Address Bar Spoofing in Mail Message Framework

Title source: llm
STIX 2.1

Description

An issue was discovered in certain Apple products. iOS before 11.2 is affected. The issue involves the "Mail Message Framework" component. It allows remote attackers to spoof the address bar via a crafted web site.

References (7)

Core 7
Core References
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT208334
Vendor Advisory x_refsource_confirm
https://support.apple.com/kb/HT210721
Vendor Advisory x_refsource_confirm
https://support.apple.com/kb/HT210724
Vendor Advisory x_refsource_confirm
https://support.apple.com/kb/HT210722
Mailing List mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2019/Oct/56
Mailing List mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2019/Oct/49
Mailing List mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2019/Oct/54

Scores

CVSS v3 4.3
EPSS 0.0091
EPSS Percentile 56.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Details

Status published
Products (1)
apple/iphone_os < 11.2
Published Dec 27, 2017
Tracked Since Feb 18, 2026