PT-2017-7823 · Apple · Safari Technology Preview

Kamil Frankowicz

·

Published

2017-04-03

·

Updated

2017-04-11

·

CVE-2016-10226

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Safari Technology Preview Release 18
Description The issue allows remote attackers to cause a denial of service, resulting in an application crash, via crafted JavaScript code. This is related to the mishandling of code in the operatorString function, and involves files such as MacroAssemblerARM64.h, MacroAssemblerX86Common.h, and WasmB3IRGenerator.cpp.
Recommendations For Safari Technology Preview Release 18, consider avoiding the execution of crafted JavaScript code until a fix is available. As a temporary workaround, restricting JavaScript execution may help minimize the risk of exploitation.

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-10226

Affected Products

Safari Technology Preview