PatchSiren cyber security CVE debrief
CVE-2017-2363 Apple CVE debrief
CVE-2017-2363 is an Apple WebKit information-disclosure issue that can let a crafted website bypass the browser’s Same Origin Policy and read sensitive data. The CVE is rated CVSS 6.5 (Medium) and affects iOS, Safari, tvOS, and watchOS versions listed in the NVD record.
- Vendor
- Apple
- Product
- Safari
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-20
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-20
- Advisory updated
- 2026-05-13
Who should care
Security teams managing Apple endpoints and browsers should care most, especially if they support older iOS, Safari, tvOS, or watchOS releases still in use. Web application and identity teams should also care because the issue is triggered by a crafted website and can expose data from browser sessions.
Technical summary
The NVD record classifies the weakness as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) and gives the vector CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N. The affected versions listed are iOS before 10.2.1, Safari before 10.0.3, tvOS before 10.1.1, and watchOS before 3.1.3; the record also includes WebKitGTK+ before 2.16.3. The issue is described as a Same Origin Policy bypass caused by a crafted website, which makes user interaction necessary but leaves confidentiality at risk.
Defensive priority
Medium
Recommended defensive actions
- Verify whether any managed Apple devices or Safari installations are at or below the affected versions listed in the NVD record.
- Prioritize patching or upgrading to the fixed versions identified by Apple and reflected in the CVE record.
- Treat access to untrusted websites as a higher-risk activity on unpatched systems until remediation is complete.
- Review browser- and WebKit-dependent applications for exposure on older Apple platforms and update them as part of endpoint maintenance.
- Use the vendor advisories linked in the record to confirm platform-specific remediation guidance.
Evidence notes
This debrief is based on the official CVE/NVD record for CVE-2017-2363, which states the issue was published on 2017-02-20 and later modified in NVD on 2026-05-13. The record identifies Apple as the vendor, WebKit as the affected component, and the impact as Same Origin Policy bypass leading to sensitive information disclosure. NVD also lists vendor advisories and third-party references for the issue; the record does not indicate KEV inclusion.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-2363 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-2363
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-2363 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-2363
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://security.gentoo.org/glsa/201706-15
[email protected] - Third Party Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://support.apple.com/HT207482
[email protected] - Vendor Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://support.apple.com/HT207484
[email protected] - Vendor Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://support.apple.com/HT207485
[email protected] - Vendor Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://support.apple.com/HT207487
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.