ZeroHour

CVE-2017-7006

CVSS 3.0
5.3 medium
EPSS
1%p70
Published
()
Modified
Description

An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct a timing side-channel attack to bypass the Same Origin Policy and obtain sensitive information via a crafted web site that uses SVG filters.

Vendors
apple
Products
safari, iphone os, tvos, webkit
Weakness
CWE-203
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.