High severity7.8NVD Advisory· Published Dec 25, 2017· Updated May 13, 2026
CVE-2017-13861
CVE-2017-13861
Description
An issue was discovered in certain Apple products. iOS before 11.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "IOSurface" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- www.securityfocus.com/bid/102134nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1039952nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1039953nvdThird Party AdvisoryVDB Entry
- support.apple.com/HT208325nvdVendor Advisory
- support.apple.com/HT208327nvdVendor Advisory
- support.apple.com/HT208334nvdVendor Advisory
- www.exploit-db.com/exploits/43320/nvdThird Party AdvisoryVDB Entry
- packetstormsecurity.com/files/153148/Safari-Webkit-Proxy-Object-Type-Confusion.htmlnvd
News mentions
0No linked articles in our index yet.