An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The issue involves the "Security" component. A race condition allows attackers to bypass intended entitlement restrictions for sending XPC messages via a crafted app.
References
Link | Resource |
---|---|
https://support.apple.com/HT207797 | Vendor Advisory |
https://support.apple.com/HT207798 | Vendor Advisory |
https://www.exploit-db.com/exploits/42145/ | Third Party Advisory VDB Entry |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: apple
Published: 2018-04-03T06:00:00
Updated: 2018-04-03T09:57:01
Reserved: 2017-03-17T00:00:00
Link: CVE-2017-7004
JSON object: View
NVD Information
Status : Analyzed
Published: 2018-04-03T06:29:01.767
Modified: 2018-05-04T16:04:29.397
Link: CVE-2017-7004
JSON object: View
Redhat Information
No data.
CWE