CVE-2017-7004

HIGH

Apple <10.3.2, <10.12.5 - Privilege Escalation

Title source: llm

Description

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The issue involves the "Security" component. A race condition allows attackers to bypass intended entitlement restrictions for sending XPC messages via a crafted app.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Google Security Research · clocalmultiple
https://www.exploit-db.com/exploits/42145

Scores

CVSS v3 7.0
EPSS 0.0561
EPSS Percentile 90.4%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-362
Status published
Products (2)
apple/iphone_os < 10.3.2
apple/mac_os_x < 10.12.5
Published Apr 03, 2018
Tracked Since Feb 18, 2026