cbcvebase.
CVE-2017-7043
published 2017-07-20

CVE-2017-7043: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected…

PriorityP262high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EXPLOIT
EPSS
6.31%
92.9th percentile
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

Affected

11 ranges
VendorProductVersion rangeFixed in
appleicloud< 6.2.26.2.2
appleicloud_for_windows
appleios
appleiphone_os< 10.3.310.3.3
appleitunes< 12.6.212.6.2
appleitunes_12.6.2_for_windows
applesafari< 10.1.210.1.2
applesafari
appletvos< 10.2.210.2.2
appletvos
debianwebkit2gtk< webkit2gtk 2.16.3-2 (bookworm)webkit2gtk 2.16.3-2 (bookworm)

Detection & IOCsextracted from sources · hover to see the quote

commanddocument.execCommand("bold", false)
commandimg.style.removeProperty("-webkit-appearance")
commandimg.setAttribute("aria-expanded", "false")
  • The vulnerability is a Use-After-Free in WebCore::AccessibilityRenderObject::handleAriaExpandedChanged, triggered by manipulating aria-expanded attribute on an image element inside a visibility:collapse div combined with execCommand('bold') in an error event handler.
  • Exploit PoC uses a div with CSS 'visibility: collapse' containing an img element, with an onerror event handler that calls execCommand bold, removes -webkit-appearance, and sets aria-expanded to false — monitor for this pattern in web content.
  • Crash originates in WebCore::jsElementPrototypeFunctionSetAttribute within WebCore.framework — look for WebKit process crashes involving setAttribute calls on accessibility-related attributes.
  • The UAF is triggered via WebCore::ImageLoader::dispatchPendingErrorEvent — exploitation requires an image load error event to fire, which can be detected as an img src error combined with aria attribute manipulation.
  • ·Affected platforms are iOS before 10.3.3, Safari before 10.1.2, iCloud for Windows before 6.2.2, iTunes for Windows before 12.6.2, and tvOS before 10.2.2 — detection should be scoped to unpatched versions of these products.
  • ·On Debian-based Linux systems (bookworm, bullseye, forky, sid, trixie), the issue is resolved in webkit2gtk version 2.16.3-2.

CVSS provenance

nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8LOW
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.