PatchSiren cyber security CVE debrief
CVE-2017-2366 Apple CVE debrief
CVE-2017-2366 is a high-severity Apple WebKit memory-corruption issue that can be triggered by a crafted website. The CVE description says it may allow remote code execution or cause a denial of service through application crash, affecting iOS, Safari, iCloud, and iTunes versions released before the fixed updates named in the record.
- Vendor
- Apple
- Product
- Unknown
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-20
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-20
- Advisory updated
- 2026-05-13
Who should care
Organizations and individuals running Apple software in the affected ranges should care, especially fleets with Safari-based browsing exposure or managed iOS/iCloud/iTunes deployments. Security teams should prioritize systems that may visit untrusted web content, since the trigger path is remote and requires only user interaction with a crafted website.
Technical summary
NVD classifies the weakness as CWE-119 and assigns CVSS 3.0 8.8 (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). The vulnerable component is WebKit, and the attack surface is network-based through a crafted website. Affected versions in the CVE record are iOS before 10.2.1, Safari before 10.0.3, iCloud before 6.1.1, and iTunes before 12.5.5; the NVD CPE data maps these to iOS 10.2.0 and earlier, Safari 10.0.2 and earlier, iCloud 6.1.0 and earlier, and iTunes 12.5.4 and earlier.
Defensive priority
High. The combination of remote delivery, no privileges required, user interaction, and potential code execution makes this a priority patch item for exposed Apple endpoints and managed user devices.
Recommended defensive actions
- Update iOS to 10.2.1 or later on affected devices.
- Update Safari to 10.0.3 or later where applicable.
- Update iCloud to 6.1.1 or later on affected systems.
- Update iTunes to 12.5.5 or later on affected systems.
- Review Apple vendor advisories and related release notes linked from the CVE record for product-specific remediation guidance.
- Prioritize devices likely to browse untrusted websites or open web content in WebKit-based components.
- Verify patch compliance across managed Apple fleets and confirm vulnerable versions are no longer present.
Evidence notes
This debrief is based on the NVD CVE record and the Apple-linked vendor/reference entries in the supplied corpus. The original CVE publication time is 2017-02-20T08:59:05.213Z; the later 2026-05-13 modification timestamp reflects record maintenance, not the issue date. No exploit instructions are included; all versioning and impact statements come from the provided CVE description and NVD metadata.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-2366 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-2366
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-2366 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-2366
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://security.gentoo.org/glsa/201706-15
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://support.apple.com/HT207481
[email protected] - Vendor Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://support.apple.com/HT207482
[email protected] - Vendor Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://support.apple.com/HT207484
[email protected] - Vendor Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://support.apple.com/HT207486
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.