CVE-2017-17821: Apple Safari

Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.

WTF/wtf/FastBitVector.h in WebKit, as distributed in Safari Technology Preview Release 46, allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact because it calls the FastBitVectorWordOwner::resizeSlow function (in WTF/wtf/FastBitVector.cpp) for a purpose other than initializing a bitvector size, and resizeSlow mishandles cases where the old array length is greater than the new array length.

Affected products

  • Apple Safari: version 46 only

Published 2017-12-21. Last modified 2026-06-17.