PT-2017-15407 · Apple · Javascriptcore+2
Niklasb
+1
·
Published
2017-05-04
·
Updated
2019-10-03
·
CVE-2017-2491
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apple Safari versions prior to 10.3
Description
The issue is related to a use after free vulnerability in the String.replace method in JavaScriptCore. This allows remote attackers to execute arbitrary code via a crafted web page or a crafted file. The vulnerability was demonstrated at Pwn2Own, indicating its potential for real-world exploitation.
Recommendations
For versions prior to 10.3, update to iOS 10.3 or later to resolve the issue.
Exploit
Fix
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Javascriptcore
Safari
Ios