VulnerabilityModified
CVE-2017-13852
It allows attackers to monitor arbitrary apps via a crafted app that accesses process information at a high rate.
LOW 3.3EPSS 0.83%
Does this matter?
Lower severity and a low EPSS score (0.83%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in certain Apple products. iOS before 11.1 is affected. macOS before 10.13.1 is affected. tvOS before 11.1 is affected. watchOS before 4.1 is affected. The issue involves the "Kernel" component. It allows attackers to monitor arbitrary apps via a crafted app that accesses process information at a high rate.
- CVSS 3.0
- 3.3 LOWCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
- EPSS
- 0.83% probability · 56th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- apple/iphone os · apple/mac os x · apple/tvos · apple/watchos
- Source
- product-security@apple.com
References
- https://support.apple.com/HT208219Vendor Advisory
- https://support.apple.com/HT208220Vendor Advisory
- https://support.apple.com/HT208221Vendor Advisory
- https://support.apple.com/HT208222Vendor Advisory
- https://support.apple.com/HT208219Vendor Advisory
- https://support.apple.com/HT208220Vendor Advisory
- https://support.apple.com/HT208221Vendor Advisory
- https://support.apple.com/HT208222Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.