CVE-2017-13868 is a memory-read restriction bypass vulnerability affecting the Kernel component in iOS before 11.2, macOS before 10.13.2, tvOS before 11.2, and watchOS before 4.2. This medium-severity vulnerability (CVSS 5.5) allows an attacker to gain access to sensitive memory information via a crafted application, leading to a high impact on confidentiality. While there is no evidence of active exploitation or Metasploit/Nuclei modules, an ExploitDB entry (EDB-44234) exists for a related information leak in macOS High Sierra. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 11.2CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
< 10.13.2CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* | ||
< 11.2CPE matchmatch criteria | cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* | ||
< 4.2CPE matchmatch criteria | cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.