CVE-2017-13890 is a high-severity vulnerability affecting Apple macOS versions prior to 10.13.4 and 10.13, specifically within the "CoreTypes" component. This flaw allows remote attackers to force disk-image mounting through a specially crafted website, potentially leading to unauthorized data access or system compromise. With a CVSS score of 7.4, it requires user interaction but has a low attack complexity and high impact on integrity. While there's no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), it has received some community discussion and media coverage, including a BleepingComputer article detailing its discovery as a zero-day.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.13.4CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.