PatchSiren cyber security CVE debrief
CVE-2017-2361 Apple CVE debrief
CVE-2017-2361 is a cross-site scripting (XSS) issue in Apple's Help Viewer component affecting macOS versions before 10.12.3. According to NVD, the issue can be triggered through a crafted website and carries a medium CVSS 3.0 score of 6.1. Apple’s advisory and the NVD record both indicate the vulnerable exposure is limited to older macOS releases.
- Vendor
- Apple
- Product
- Unknown
- CVSS
- MEDIUM 6.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-20
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-20
- Advisory updated
- 2026-05-13
Who should care
MacOS administrators, security teams managing Apple fleets, and users or support teams responsible for systems still running macOS 10.12.2 or earlier should care most. Any environment that allows unpatched or legacy Macs to browse the web or open Help Viewer content has relevant exposure.
Technical summary
NVD classifies the weakness as CWE-79 (cross-site scripting). The published CVSS vector is CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N, indicating network reachability, no privileges required, user interaction required, and limited confidentiality/integrity impact with no availability impact. The affected CPE scope in NVD is macOS versions up to and including 10.12.2; Apple addresses the issue in macOS 10.12.3.
Defensive priority
Medium priority for systems that remain on affected macOS versions. The issue is user-interaction dependent and limited in impact, but it is remotely reachable through a crafted website and should be remediated on any still-supported or legacy Mac fleet.
Recommended defensive actions
- Upgrade affected Macs to macOS 10.12.3 or later, consistent with Apple's advisory and the NVD affected-version range.
- Inventory any Macs still running macOS 10.12.2 or earlier and prioritize them for remediation or isolation.
- Treat unexpected or suspicious web content as higher risk on legacy systems until they are updated.
- If a system cannot be upgraded immediately, restrict its web exposure and limit use on untrusted websites until it is remediated.
Evidence notes
The NVD record for CVE-2017-2361 identifies Apple macOS before 10.12.3 as affected, with vulnerability in the Help Viewer component and CWE-79 as the weakness class. The CVSS vector shows network-based attack, user interaction required, and low confidentiality/integrity impact. Apple's linked vendor advisory is provided in the source corpus as support.apple.com/HT207483.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-2361 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-2361
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-2361 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-2361
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://support.apple.com/HT207483
[email protected] - Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://www.exploit-db.com/exploits/41443/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.