CVE-2017-7047

HIGH

Apple <10.3.3, <10.12.6, <10.2.2, <3.2.3 - RCE/DoS

Title source: llm

Description

An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. watchOS before 3.2.3 is affected. The issue involves the "libxpc" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

Exploits (3)

nomisec WORKING POC 7 stars
by JosephShenton · poc
https://github.com/JosephShenton/Triple_Fetch-Kernel-Creds
nomisec WORKING POC
by q1f3 · poc
https://github.com/q1f3/Triple_fetch
exploitdb WORKING POC VERIFIED
by Google Security Research · textlocalmultiple
https://www.exploit-db.com/exploits/42407

Scores

CVSS v3 8.8
EPSS 0.2249
EPSS Percentile 95.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Classification

CWE
CWE-119
Status draft

Affected Products (4)

apple/iphone_os < 10.3.3
apple/mac_os_x < 10.12.6
apple/tvos < 10.2.2
apple/watchos < 3.2.3

Timeline

Published Jul 20, 2017
Tracked Since Feb 18, 2026