CVE-2017-13849
MEDIUMiPhone OS < 11.1 - Denial of Service in CoreText via Crafted Text File
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-13849. PoCs published by Russian Otter.
AI-analyzed exploit summary This exploit generates a maliciously crafted Unicode payload that triggers a DoS condition in iOS < 11.1 by exploiting a vulnerability in Core-Text. The payload causes thread crashes or extreme lag when displayed in affected applications.
Description
An issue was discovered in certain Apple products. iOS before 11.1 is affected. tvOS before 11.1 is affected. watchOS before 4.1 is affected. The issue involves the "CoreText" component. It allows remote attackers to cause a denial of service (application crash) via a crafted text file.
Exploits (1)
This exploit generates a maliciously crafted Unicode payload that triggers a DoS condition in iOS < 11.1 by exploiting a vulnerability in Core-Text. The payload causes thread crashes or extreme lag when displayed in affected applications.
References (6)
Scores
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H