CVE-2017-13849

MEDIUM

iPhone OS < 11.1 - Denial of Service in CoreText via Crafted Text File

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2017-13849. PoCs published by Russian Otter.

AI-analyzed exploit summary This exploit generates a maliciously crafted Unicode payload that triggers a DoS condition in iOS < 11.1 by exploiting a vulnerability in Core-Text. The payload causes thread crashes or extreme lag when displayed in affected applications.

Description

An issue was discovered in certain Apple products. iOS before 11.1 is affected. tvOS before 11.1 is affected. watchOS before 4.1 is affected. The issue involves the "CoreText" component. It allows remote attackers to cause a denial of service (application crash) via a crafted text file.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Russian Otter · pythondosios
https://www.exploit-db.com/exploits/43161

This exploit generates a maliciously crafted Unicode payload that triggers a DoS condition in iOS < 11.1 by exploiting a vulnerability in Core-Text. The payload causes thread crashes or extreme lag when displayed in affected applications.

Classification
Working Poc 100%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: iOS < 11.1 (Core-Text)
No auth needed
Prerequisites: Target device running iOS < 11.1 · Application that renders Unicode text (e.g., Signal, Instagram)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT208222
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/43161/
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/101691
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT208220
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT208219
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1039703

Scores

CVSS v3 5.5
EPSS 0.0378
EPSS Percentile 88.6%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Details

CWE
CWE-20
Status published
Products (3)
apple/iphone_os < 11.1
apple/tvos < 11.1
apple/watchos < 4.1
Published Nov 13, 2017
Tracked Since Feb 18, 2026