4.3
CVSSv2

CVE-2017-2371

Published: 20/02/2017 Updated: 23/01/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

An issue exists in certain Apple products. iOS prior to 10.2.1 is affected. The issue involves the "WebKit" component, which allows remote malicious users to launch popups via a crafted web site.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple iphone os

Vendor Advisories

Several security issues were fixed in WebKitGTK+ ...
An issue has been found in the handling of blocking popups in WebKitGTK+ before 2144, allowing a malicious website to open popups ...

Exploits

<!-- Source: bugschromiumorg/p/project-zero/issues/detail?id=1050 The second argument of windowopen is a name for the new window If there's a frame that has same name, it will try to load the URL in that If not, it just tries to create a new window and pop-up But without the user's click event, its attempt will fail Here's some ...