CVE-2017-13861
HIGHSafari Webkit Proxy Object Type Confusion
Title source: metasploitDescription
An issue was discovered in certain Apple products. iOS before 11.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "IOSurface" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by Google Security Research · textdosmultiple
https://www.exploit-db.com/exploits/43320
metasploit
WORKING POC
MANUAL
by saelo, niklasb, Ian Beer, siguza · rubypocapple_ios
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/apple_ios/browser/webkit_createthis.rb
References (8)
Scores
CVSS v3
7.8
EPSS
0.6849
EPSS Percentile
98.6%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
CWE
CWE-119
Status
published
Products (3)
apple/iphone_os
< 11.2
apple/tvos
< 11.2
apple/watchos
< 4.2
Published
Dec 25, 2017
Tracked Since
Feb 18, 2026