CVE-2017-6976 is a medium-severity vulnerability affecting iOS versions prior to 10.3, specifically within the "Sandbox Profiles" component. An attacker could exploit this by crafting a malicious application to bypass intended access restrictions, potentially gaining unauthorized access to iCloud user records. The attack requires user interaction (UI:R) and local access (AV:L), but has high confidentiality impact (C:H). There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.3CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.