CVE-2017-2364
CVE-2017-2364 is an Apple WebKit issue affecting iOS before 10.2.1 and Safari before 10.0.3. A remote attacker could use a crafted website to bypass the Same Origin Policy and read sensitive information, with user interaction required.
These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2017-2364 is an Apple WebKit issue affecting iOS before 10.2.1 and Safari before 10.0.3. A remote attacker could use a crafted website to bypass the Same Origin Policy and read sensitive information, with user interaction required.
CVE-2017-2363 is an Apple WebKit information-disclosure issue that can let a crafted website bypass the browser’s Same Origin Policy and read sensitive data. The CVE is rated CVSS 6.5 (Medium) and affects iOS, Safari, tvOS, and watchOS versions listed in the NVD record.
CVE-2017-2362 is an Apple WebKit memory-corruption issue published on 2017-02-20. According to the CVE record and Apple-linked advisories in the source corpus, a crafted website could trigger arbitrary code execution or a denial of service on affected systems. The vulnerable products listed in the record are iOS before 10.2.1, Safari before 10.0.3, and tvOS before 10.1.1.
CVE-2017-2361 is a cross-site scripting (XSS) issue in Apple's Help Viewer component affecting macOS versions before 10.12.3. According to NVD, the issue can be triggered through a crafted website and carries a medium CVSS 3.0 score of 6.1. Apple’s advisory and the NVD record both indicate the vulnerable exposure is limited to older macOS releases.
CVE-2017-2360 is a high-severity Apple kernel use-after-free disclosed on 2017-02-20. According to the NVD record, a crafted app could trigger the flaw and lead to arbitrary code execution in a privileged context or a denial of service. Apple listed fixes for iOS, macOS, tvOS, and watchOS in the vendor advisories referenced by NVD.
CVE-2017-2359 is a Safari spoofing issue in Apple products. NVD lists Safari versions through 10.0.2 as affected, and the flaw could be triggered by a crafted website to spoof the address bar. Apple’s advisory HT207484 is referenced as the vendor fix notice.
CVE-2017-2358 is an Apple macOS Graphics Drivers issue affecting macOS versions before 10.12.3. According to the CVE description, a crafted app could trigger memory corruption leading to arbitrary code execution in a privileged context or a denial of service.
CVE-2017-2357 describes an information disclosure issue in Apple’s IOAudioFamily component on macOS before 10.12.3. According to NVD, a crafted app could trigger the leak and reveal sensitive kernel memory-layout information, making this primarily a local reconnaissance issue rather than an execution flaw.
CVE-2017-2356 is an Apple WebKit memory corruption issue reported for multiple Apple products. According to the CVE/NVD record, a crafted web site could trigger arbitrary code execution or a denial of service, with affected versions including iOS before 10.2.1, Safari before 10.0.3, iCloud before 6.1.1, iTunes before 12.5.5, and tvOS before 10.1.1. The vulnerability was published on 2017-02-20 and is rate [truncated]
CVE-2017-2355 is an Apple WebKit vulnerability affecting multiple Apple products before their fixed releases. According to the CVE description, a crafted website could trigger uninitialized memory access leading to application crash, and potentially remote code execution. The published record assigns a high severity score and a network-facing attack vector, but it also requires user interaction.
CVE-2017-2354 is a WebKit memory-corruption issue in Apple products that can be triggered by a crafted website. NVD describes the impact as arbitrary code execution or a denial of service via application crash. The affected versions listed in the source corpus are iOS before 10.2.1, Safari before 10.0.3, iCloud before 6.1.1, iTunes before 12.5.5, and tvOS before 10.1.1; NVD also lists WebKitGTK+ before 2.16.3.
CVE-2017-2353 is a high-severity macOS Bluetooth use-after-free that Apple addressed in macOS 10.12.3. According to the NVD record, affected systems include macOS versions up to 10.12.2, and exploitation could lead to arbitrary code execution in a privileged context or denial of service. The published CVSS v3.0 vector indicates a local attack that requires user interaction, but can still have high impact [truncated]
CVE-2017-2352 is a Medium-severity Apple issue affecting the Apple Watch "Unlock with iPhone" path. According to the supplied record, the flaw can bypass the Watch’s wrist-presence protection and allow the device to be unlocked through unspecified vectors. The record’s CVSS 3.0 vector indicates a physically proximate, low-complexity attack with high integrity impact and no direct confidentiality or availa [truncated]
CVE-2017-2351 describes a low-severity Apple iOS issue affecting devices before 10.2.1. According to the CVE description, a physically proximate attacker could bypass Activation Lock and reach the home screen through unspecified vectors involving the Wi‑Fi component. NVD classifies the weakness as CWE-20 and rates the attack vector as physical, which limits exposure to nearby attackers rather than remote [truncated]
CVE-2017-2350 describes a WebKit flaw affecting Apple platforms that could let a remote attacker use a crafted website to bypass the Same Origin Policy and read sensitive information. Apple listed affected versions of iOS before 10.2.1, Safari before 10.0.3, and tvOS before 10.1.1. NVD also maps WebKitGTK+ before 2.16.3 to this issue. The impact is confidentiality-focused and requires user interaction thr [truncated]
CVE-2016-7765 is a low-severity Apple iOS privacy issue involving the Clipboard component. On affected devices, a physically proximate attacker may be able to view clipboard contents while the device is in the lockscreen state, exposing sensitive copied information. The supplied sources place the affected range before Apple’s iOS 10.2 fix, with NVD’s machine-readable data narrowing the bound to iPhone OS [truncated]
CVE-2016-7762 is a WebKit cross-site scripting issue affecting Apple iOS versions before 10.2. The vulnerability was publicly recorded on 2017-02-20, and NVD classifies it as medium severity with network attack vector and required user interaction. The issue can allow malicious web content to influence Safari in a way consistent with XSS behavior, so updating to the fixed iOS release is the key mitigation.
CVE-2016-7761 is a medium-severity local information-disclosure issue in Apple macOS WiFi handling. According to the NVD record, macOS versions through 10.12.1 are affected, and a local user could obtain sensitive network-configuration information by leveraging global storage. Apple’s advisory is referenced by NVD, and the issue is listed as fixed in macOS 10.12.2.
CVE-2016-7759 is an information-disclosure issue in Apple's Springboard component affecting iOS before 10. According to the NVD record, a physically proximate attacker could view application snapshots shown in the Task Switcher and learn sensitive information. NVD maps this to CWE-200 and rates it CVSS 4.3 (MEDIUM).
CVE-2016-7742 is a high-severity Apple macOS vulnerability in the xar archive component. According to the CVE description, a crafted archive can trigger use of uninitialized memory locations and allow arbitrary code execution; Apple’s advisory is referenced by NVD as HT207423. The record was published on 2017-02-20 and last modified by NVD on 2026-05-13.
CVE-2016-7714 is a low-severity Apple information-disclosure issue in the IOKit component. According to the supplied records, local users could obtain sensitive kernel memory-layout information on affected devices. Apple listed fixes for iOS before 10.2, macOS before 10.12.2, and watchOS before 3.1.3.
CVE-2016-7667 is an Apple CoreText issue that can be triggered remotely with a crafted string and result in denial of service. The CVE description states that iOS before 10.2 and macOS before 10.12.2 are affected, while the NVD record maps vulnerable CPE ranges to iPhone OS through 10.1.1 and macOS through 10.12.1. Apple vendor advisories are referenced by NVD, and the issue was published on 2017-02-20. T [truncated]
CVE-2016-7666 is an Apple Transporter information-disclosure issue affecting versions before 1.9.2. NVD says the flaw is in the iTMSTransporter component and can leak sensitive information when a crafted EPUB is processed. The published CVSS score is 5.5 (Medium), reflecting local access with user interaction and confidentiality impact only.
CVE-2016-7665 describes a denial-of-service issue in Apple’s iOS Graphics Driver component affecting iOS versions before 10.2. The public description says a crafted video could be used by remote attackers to disrupt service. Apple’s advisory and NVD record are the key public references for affected versions and remediation context.
CVE-2016-7664 is a low-severity Apple iOS information disclosure issue involving the Accessibility component on the lockscreen. According to the supplied record, a physically proximate attacker could leverage excessive lockscreen options to obtain sensitive photo and contact information on affected devices running iOS before 10.2.
CVE-2016-7663 is a critical Apple CoreFoundation vulnerability published on 2017-02-20. According to NVD, a crafted string could trigger memory corruption and an application crash, and may allow remote code execution on affected iOS, macOS, and watchOS versions.
CVE-2016-7662 is an Apple certificate-validation weakness in the Security component. In affected iOS, macOS, and watchOS releases, a remote attacker could spoof certificates, weakening trust in encrypted connections and enabling man-in-the-middle style deception. Apple’s fixed releases are the relevant defensive action for exposed devices.
CVE-2016-7661 is a local privilege-escalation issue in Apple’s Power Management component. The record says the weakness could let a local user gain privileges through unspecified vectors related to Mach port name references. Apple devices running iOS before 10.2 and macOS before 10.12.2 are identified as affected in the CVE description and NVD record.
CVE-2016-7660 is a local privilege-escalation issue in Apple’s syslog component. The supplied CVE description says local users could gain elevated privileges through unspecified vectors involving Mach port name references. Apple’s advisories and the NVD record show this was publicly disclosed on 2017-02-20 and fixed in later iOS, macOS, and watchOS releases.
CVE-2016-7659 is an Apple Audio-component memory corruption issue that can be triggered by a crafted file. The supplied record describes remote code execution as well as denial of service via application crash. NVD assigns a high-severity CVSS 3.0 score (8.8) with network attack vector and user interaction required.