An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The issue involves the "Security" component. A race condition allows attackers to bypass intended entitlement restrictions for sending XPC messages via a crafted app.
2018-04-03T06:29:01.767
2024-11-21T03:30:57.410
Modified
CVSSv3.0: 7.0 (HIGH)
AV:N/AC:H/Au:N/C:P/I:P/A:P
4.9
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | apple | iphone_os | < 10.3.2 | Yes |
Operating System | apple | mac_os_x | < 10.12.5 | Yes |