CVE-2012-2871: Apple iPhone OS
Medium severity, CVSS 6.8. EPSS: 2.4% chance of exploitation in the next 30 days.
libxml2 2.9.0-rc1 and earlier, as used in Google Chrome before 21.0.1180.89, does not properly support a cast of an unspecified variable during handling of XSL transforms, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document, related to the _xmlNs data structure in include/libxml/tree.h.
Affected products
- Apple iPhone OS: up to and including 6.1.4; version 1.0.0 only; version 1.0.1 only; version 1.0.2 only; version 1.1.0 only; version 1.1.1 only; …
- Google Chrome: up to and including 21.0.1180.88; version 21.0.1180.0 only; version 21.0.1180.1 only; version 21.0.1180.2 only; version 21.0.1180.31 only; version 21.0.1180.32 only; …
- Xmlsoft LIBXML2: up to and including 2.9.0
Published 2012-08-31. Last modified 2026-06-16.