High severity7.5NVD Advisory· Published Dec 25, 2017· Updated Jun 17, 2026
CVE-2017-13903
CVE-2017-13903
Description
An issue was discovered in certain Apple products. iOS before 11.2.1 is affected. tvOS before 11.2.1 is affected. The issue involves the "HomeKit" component. It allows remote attackers to modify the application state by leveraging incorrect message handling, as demonstrated by use of an Apple Watch to obtain an encryption key and unlock a door.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*range: <11.2.1
- (no CPE)range: <11.2.1
- Range: <11.2.1
- Range: <11.2.1
Patches
Vulnerability mechanics
References
5- www.securityfocus.com/bid/102182nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1040008nvdThird Party AdvisoryVDB Entry
- support.apple.com/HT208357nvdVendor Advisory
- support.apple.com/HT208359nvdVendor Advisory
- www.engadget.com/2017/12/21/apple-ignored-a-major-homekit-security-flaw-for-six-weeks/nvdPress/Media Coverage
News mentions
0No linked articles in our index yet.