CVE-2017-13852

LOW

Apple <11.1, <10.13.1, <4.1, <11.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

An issue was discovered in certain Apple products. iOS before 11.1 is affected. macOS before 10.13.1 is affected. tvOS before 11.1 is affected. watchOS before 4.1 is affected. The issue involves the "Kernel" component. It allows attackers to monitor arbitrary apps via a crafted app that accesses process information at a high rate.

References (4)

Core 4
Core References
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT208221
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT208222
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT208220
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT208219

Scores

CVSS v3 3.3
EPSS 0.0083
EPSS Percentile 53.2%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Details

CWE
CWE-200
Status published
Products (4)
apple/iphone_os < 11.1
apple/mac_os_x < 10.13.1
apple/tvos < 11.1
apple/watchos < 4.1
Published Nov 13, 2017
Tracked Since Feb 18, 2026