CVE-2017-2474 is an off-by-one error in the Kernel component of Apple iOS before 10.3, macOS before 10.12.4, tvOS before 10.2, and watchOS before 3.2. This vulnerability allows attackers to execute arbitrary code in a privileged context through a crafted application. It carries a CVSSv3 score of 7.8 (HIGH), indicating a high impact on confidentiality, integrity, and availability, with a local attack vector and user interaction required. While not listed on the KEV catalog or Hot List, an exploit (EDB-41793) for macOS/iOS Kernel 10.12.3 exists, though there is no evidence of active widespread exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.2.1CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
<= 10.12.3CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* | ||
<= 10.1.1CPE matchmatch criteria | cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* | ||
<= 3.1.3CPE matchmatch criteria | cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.