CVE-2017-7085 describes a spoofing vulnerability affecting Apple iOS before version 11 and Safari before version 11, specifically within the Safari component. This medium-severity flaw (CVSS 6.5) allows remote attackers to deceive users by spoofing the address bar, potentially leading to phishing or other social engineering attacks. While no active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB) is indicated, the vulnerability received some community discussion and media coverage at the time of its disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.1.2CPE matchmatch criteria | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* | ||
<= 10.3.3CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.