CVE-2017-2492 is a Universal Cross-Site Scripting (UXSS) vulnerability in the JavaScriptCore component of Apple iOS, Safari, and tvOS, affecting versions prior to 10.3, 10.1, and 10.2 respectively. This medium-severity flaw (CVSS 6.1) allows remote attackers to execute UXSS attacks by tricking users into visiting a crafted website that exploits prototype mishandling. While the vulnerability is publicly known, there is no evidence of active exploitation, readily available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding it.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.1CPE matchmatch criteria | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* | ||
< 10.3CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
< 10.2CPE matchmatch criteria | cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.