CVE-2017-13861
An issue was discovered in certain Apple products. iOS before 11.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "IOSurface" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
- Apple Iphone Os
- < 11.2
- Apple Tvos
- < 11.2
- Apple Watchos
- < 4.2
- Fix
- Available
- CVSS 2.0
- 9.3 HIGH
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 14.9% (96th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2017-12-25
CVE-2017-13861 at NVD
8 known exploits for CVE-2017-13861
Proof-of-concept code and exploit modules indexed by Sploitus
π macOS 10.13.6 Reference Leak
Safari Webkit Proxy Object Type Confusion Exploit
Safari Webkit Proxy Object Type Confusion
Safari Webkit Proxy Object Type Confusion
iOS / macOS - task_swap_mach_voucher() Use-After-Free Exploit
iOSmacOS - task_swap_mach_voucher() Use-After-Free
iOS/MacOS kernel double free due to IOSurfaceRootUserClient not respecting MIG ownership rules(CVE-2017-13861)
Apple macOS/iOS - Kernel Double Free due to IOSurfaceRootUserClient not Respecting MIG Ownership Rules