CVE-2017-6979 is a race condition vulnerability in the IOSurface component of Apple's iOS (before 10.3.2), macOS (before 10.12.5), tvOS (before 10.2.1), and watchOS (before 3.2.2). This vulnerability has a CVSS score of 7.0 (HIGH), indicating that an attacker could execute arbitrary code in a privileged context through a crafted application, albeit with high attack complexity and requiring user interaction. While not listed on CISA's KEV, exploit code for this kernel vulnerability has been publicly released (EDB-42555), leading to significant community discussion and media coverage, including reports of a fully working exploit.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.3.1CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
<= 10.12.4CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* | ||
<= 10.2CPE matchmatch criteria | cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* | ||
<= 3.2CPE matchmatch criteria | cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.0 Bluesky, 0.1 Mastodon, and 0.0 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.