CVE-2017-2385: Apple Safari

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

An issue was discovered in certain Apple products. Safari before 10.1 is affected. The issue involves the "Safari Login AutoFill" component. It allows local users to obtain access to locked keychain items via unspecified vectors.

Affected products

  • Apple Safari: up to and including 10.0.3

Published 2017-04-02. Last modified 2026-06-17.