CVE-2017-13865 is a memory disclosure vulnerability affecting the Kernel component in Apple iOS before 11.2, macOS before 10.13.2, tvOS before 11.2, and watchOS before 4.2. An attacker can exploit this by crafting a malicious application to bypass intended memory-read restrictions. Rated Medium severity (CVSS 5.5), it requires user interaction (UI:R) and local access (AV:L), leading to high confidentiality impact (C:H) by allowing unauthorized memory-read access. While not on the KEV catalog, an ExploitDB entry exists, and it has garnered some community discussion and media coverage, including a mention in relation to an iOS 11 jailbreak exploit.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 11.2CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
< 10.13.2CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* | ||
< 11.2CPE matchmatch criteria | cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* | ||
< 4.2CPE matchmatch criteria | cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.