An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that is mishandled during parent-tab processing.
CVSS Details
- CVSS 3.0 Base Score: 6.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade webkit2gtk | Jan 2, 2018 | Oct 22, 2017 |
| Apple Safari | — | Uninstall Apple Safari on WindowsUpgrade to Apple Safari version 11 | Sep 21, 2017 | Sep 21, 2017 |
| Debian | — | Upgrade webkit2gtk | Jul 30, 2024 | Oct 23, 2017 |
| Freebsd | — | Upgrade webkit2-gtk3 | Mar 29, 2018 | Mar 28, 2018 |
| Oracle Solaris | — | Upgrade entire/ to version 11.4-11.4.0.0.1.15.0 on Solaris 11.4 | Oct 19, 2018 | Oct 22, 2017 |
| Suse | — | Upgrade webkit2gtk-4_0-injected-bundlesUpgrade typelib-1_0-javascriptcore-4_0Upgrade libwebkit2gtk-4_0-37Upgrade libjavascriptcoregtk-4_0-18Upgrade libwebkit2gtk3-langUpgrade webkit2gtk3-develUpgrade typelib-1_0-webkit2webextension-4_0Upgrade typelib-1_0-webkit2-4_0 | Jan 30, 2018 | Oct 23, 2017 |
| Ubuntu | — | Upgrade libwebkit2gtk-4.0-37Upgrade libjavascriptcoregtk-4.0-18 | Oct 23, 2017 | Oct 23, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub