PatchSiren cyber security CVE debrief
CVE-2017-2362 Apple CVE debrief
CVE-2017-2362 is an Apple WebKit memory-corruption issue published on 2017-02-20. According to the CVE record and Apple-linked advisories in the source corpus, a crafted website could trigger arbitrary code execution or a denial of service on affected systems. The vulnerable products listed in the record are iOS before 10.2.1, Safari before 10.0.3, and tvOS before 10.1.1.
- Vendor
- Apple
- Product
- Safari
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-20
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-20
- Advisory updated
- 2026-05-13
Who should care
Organizations and individuals running affected Apple versions should care, especially environments where users browse the web from iOS, Safari, or tvOS devices. Security teams managing Apple endpoints should prioritize patch verification because the issue is network-reachable through web content and requires only user interaction.
Technical summary
NVD classifies the weakness as CWE-119 (improper restriction of operations within the bounds of a memory buffer). The CVSS v3.0 vector is AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, indicating a remotely reachable flaw that can be triggered by visiting a crafted website and may impact confidentiality, integrity, and availability. The source corpus describes both arbitrary code execution and application crash outcomes tied to WebKit memory corruption.
Defensive priority
High. The combination of remote delivery, no privileges, and the potential for code execution makes this a strong patch-priority issue for exposed Apple clients and browsers.
Recommended defensive actions
- Update iOS systems to 10.2.1 or later.
- Update Safari to 10.0.3 or later.
- Update tvOS to 10.1.1 or later.
- Verify Apple security update deployment on managed devices and confirm version compliance.
- Treat any unpatched web-browsing endpoint as exposed until remediation is confirmed.
Evidence notes
All factual claims above are limited to the supplied CVE/NVD corpus and Apple-linked references embedded in the source metadata. The record explicitly lists affected version ranges for iOS, Safari, and tvOS, the WebKit component, the crafted-website trigger, and the potential outcomes of arbitrary code execution or denial of service. The CVE published date used here is 2017-02-20.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-2362 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-2362
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-2362 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-2362
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://security.gentoo.org/glsa/201706-15
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://support.apple.com/HT207482
[email protected] - Vendor Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://support.apple.com/HT207484
[email protected] - Vendor Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://support.apple.com/HT207485
[email protected] - Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://www.exploit-db.com/exploits/41213/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.