CVE-2017-6980 is a critical memory corruption vulnerability in Apple's WebKit component, affecting iOS before 10.3.2, Safari before 10.1.1, and tvOS before 10.2.1. With a CVSS score of 8.8 (High), it allows remote attackers to execute arbitrary code or cause a denial of service simply by tricking a user into visiting a crafted website. While there is no evidence of active exploitation in the wild and minimal community discussion, a proof-of-concept exploit demonstrating the vulnerability in WebKit JSC's arrayProtoFuncSplice function is publicly available on ExploitDB. This vulnerability poses a significant risk due to its high impact and low attack complexity, despite its inactive status on the CISA KEV catalog and lack of broader media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.1CPE matchmatch criteria | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* | ||
<= 10.3.1CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
<= 10.2CPE matchmatch criteria | cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.