CVE-2012-2870: Apple iPhone OS

Medium severity, CVSS 4.3. EPSS: 2.5% chance of exploitation in the next 30 days.

libxslt 1.1.26 and earlier, as used in Google Chrome before 21.0.1180.89, does not properly manage memory, which might allow remote attackers to cause a denial of service (application crash) via a crafted XSLT expression that is not properly identified during XPath navigation, related to (1) the xsltCompileLocationPathPattern function in libxslt/pattern.c and (2) the xsltGenerateIdFunction function in libxslt/functions.c.

Affected products

  • Apple iPhone OS: up to and including 6.1.4; version 1.0.0 only; version 1.0.1 only; version 1.0.2 only; version 1.1.0 only; version 1.1.1 only; …
  • Google Chrome: up to and including 21.0.1180.88; version 21.0.1180.0 only; version 21.0.1180.1 only; version 21.0.1180.2 only; version 21.0.1180.31 only; version 21.0.1180.32 only; …
  • Xmlsoft Libxslt: up to and including 1.1.26; version 1.1.8 only; version 1.1.9 only; version 1.1.10 only; version 1.1.11 only; version 1.1.12 only; …

Published 2012-08-31. Last modified 2026-06-16.