CVE-2017-7115

HIGH

iPhone OS < 10.3.3 and tvOS < 10.2.2 - Remote Code Execution or Denial of Service via Wi-Fi Race Condition

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2017-7115. PoCs published by Google Security Research.

AI-analyzed exploit summary This exploit leverages a Wi-Fi vulnerability (CVE-2017-7115) to achieve arbitrary read/write access to physical memory on iOS devices. It uses a modified hostapd to inject crafted 802.11k frames and executes shellcode to gain control over the target device.

Description

An issue was discovered in certain Apple products. iOS before 11 is affected. tvOS before 11 is affected. The issue involves the "Wi-Fi" component. It might allow remote attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via crafted Wi-Fi traffic that leverages a race condition.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Google Security Research · textremoteios
https://www.exploit-db.com/exploits/42996

This exploit leverages a Wi-Fi vulnerability (CVE-2017-7115) to achieve arbitrary read/write access to physical memory on iOS devices. It uses a modified hostapd to inject crafted 802.11k frames and executes shellcode to gain control over the target device.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: iOS 10.2 (14C92) on iPhone 7
No auth needed
Prerequisites: SoftMAC Wi-Fi dongle (e.g., TL-WN722N) · Modified hostapd with 802.11k support · Target device connected to malicious Wi-Fi network
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/100924
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1039385
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT208113
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT208112
Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/42996/
Exploit, Issue Tracking, Mitigation, Technical Description, Third Party Advisory x_refsource_misc
https://bugs.chromium.org/p/project-zero/issues/detail?id=1317

Scores

CVSS v3 8.1
EPSS 0.0767
EPSS Percentile 93.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-362
Status published
Products (2)
apple/iphone_os < 10.3.3
apple/tvos < 10.2.2
Published Oct 23, 2017
Tracked Since Feb 18, 2026