Description
An issue was discovered in certain Apple products. iOS before 11.1 is affected. macOS before 10.13.1 is affected. tvOS before 11.1 is affected. watchOS before 4.1 is affected. The issue involves the "Kernel" component. It allows attackers to monitor arbitrary apps via a crafted app that accesses process information at a high rate.
References (4)
Core 4
Core References
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT208221
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT208222
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT208220
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT208219
Scores
CVSS v3
3.3
EPSS
0.0083
EPSS Percentile
53.2%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Details
CWE
CWE-200
Status
published
Products (4)
apple/iphone_os
< 11.1
apple/mac_os_x
< 10.13.1
apple/tvos
< 11.1
apple/watchos
< 4.1
Published
Nov 13, 2017
Tracked Since
Feb 18, 2026