CVE-2017-2516 is a memory-read restriction bypass vulnerability affecting the Kernel component in macOS versions prior to 10.12.5. An attacker can exploit this by tricking a user into installing a crafted application. With a CVSS score of 5.0 (Medium), this local vulnerability requires user interaction and could lead to high confidentiality impact by allowing unauthorized memory reads. While not actively exploited in the wild and absent from the KEV catalog, a proof-of-concept exploit for raw frame pointers exists on ExploitDB. This CVE has received minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.12.4CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.