CVE-2017-7153
Last modified
CVE-2017-7153 is a vulnerability of currently unknown severity. An issue was discovered in certain Apple products. iOS before 11.2 is affected. EPSS estimates a 1.91% chance of exploitation in the next 30 days.
Description
An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to spoof user-interface information (about whether the entire content is derived from a valid TLS session) via a crafted web site that sends a 401 Unauthorized redirect.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apple | Safari | < 11.0.2 |
| Apple | Iphone Os | < 11.2 |
| Apple | Tvos | < 11.2 |
| Apple | Watchos | < 4.2 |
| Apple | Icloud | < 7.2 |
| Apple | Itunes | < 12.7.2 |
| Canonical | Ubuntu Linux | 16.04 |
| Canonical | Ubuntu Linux | 17.10 |
References
- https://support.apple.com/HT208324Vendor Advisory
- https://support.apple.com/HT208325Vendor Advisory
- https://support.apple.com/HT208326Vendor Advisory
- https://support.apple.com/HT208327Vendor Advisory
- https://support.apple.com/HT208328Vendor Advisory
- https://support.apple.com/HT208334Vendor Advisory
- https://usn.ubuntu.com/3551-1/Third Party Advisory
- https://support.apple.com/HT208324Vendor Advisory
- https://support.apple.com/HT208325Vendor Advisory
- https://support.apple.com/HT208326Vendor Advisory
- https://support.apple.com/HT208327Vendor Advisory
- https://support.apple.com/HT208328Vendor Advisory
- https://support.apple.com/HT208334Vendor Advisory
- https://usn.ubuntu.com/3551-1/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-7153?
How severe is CVE-2017-7153?
How do I fix CVE-2017-7153?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-7147An issue was discovered in certain Apple products. The Apple…
- CVE-2017-7148An issue was discovered in certain Apple products. iOS befor…
- CVE-2017-7149An issue was discovered in certain Apple products. macOS bef…
- CVE-2017-7150An issue was discovered in certain Apple products. macOS bef…
- CVE-2017-7151A race condition was addressed with additional validation. T…
- CVE-2017-7152An issue was discovered in certain Apple products. iOS befor…
- CVE-2017-7154An issue was discovered in certain Apple products. iOS befor…
- CVE-2017-7155An issue was discovered in certain Apple products. macOS bef…
- CVE-2017-7156An issue was discovered in certain Apple products. iOS befor…
- CVE-2017-7157An issue was discovered in certain Apple products. iOS befor…
- CVE-2017-7158An issue was discovered in certain Apple products. macOS bef…
- CVE-2017-7159An issue was discovered in certain Apple products. macOS bef…
Are you affected by CVE-2017-7153?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
