Description
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. A buffer overflow allows attackers to execute arbitrary code in a privileged context via a crafted app.
In plain language
AI Worth attentionCVE-2017-2482 is a flaw in Apple’s system “Kernel” that can let a specially made app run dangerous code on your device—if you’re on older iOS/macOS/tvOS/watchOS versions, you should update.
CVE-2017-2482 is a Kernel buffer overflow (CWE-119) in iOS, macOS, tvOS, and watchOS where a crafted app can trigger memory corruption and gain privileged code execution; it’s local in the sense that the attacker must get you to run a malicious app.
What to do now
- Check whether each affected device’s operating system version is older than: iOS 10.3, macOS 10.12.4, tvOS 10.2, or watchOS 3.2.
- Update iOS to 10.3 or later.
- Update macOS to 10.12.4 or later.
- Update tvOS to 10.2 or later.
- Update watchOS to 3.2 or later.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2017-2482 and every CVE in our database. Create a free account — no credit card required.
Create Free Account