Medium severity5.3NVD Advisory· Published Jul 20, 2017· Updated May 13, 2026
CVE-2017-7006
CVE-2017-7006
Description
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct a timing side-channel attack to bypass the Same Origin Policy and obtain sensitive information via a crafted web site that uses SVG filters.
Affected products
4- cpe:2.3:a:apple:webkit:-:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- www.securityfocus.com/bid/99886nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1038950nvdThird Party AdvisoryVDB Entry
- security.gentoo.org/glsa/201710-14nvdThird Party Advisory
- support.apple.com/HT207921nvdVendor Advisory
- support.apple.com/HT207923nvdVendor Advisory
- support.apple.com/HT207924nvdVendor Advisory
News mentions
0No linked articles in our index yet.