CVE-2017-2411: Apple iPhone OS

Medium severity, CVSS 5.9. EPSS: 0.7% chance of exploitation in the next 30 days.

In iOS before 11.2, exchange rates were retrieved from HTTP rather than HTTPS. This was addressed by enabling HTTPS for exchange rates.

Affected products

  • Apple iPhone OS: before 11.2 (fixed in 11.2)

Published 2019-01-11. Last modified 2026-06-17.