First published: Tue Sep 19 2017(Updated: )
Sandbox Profiles. An application was able to determine the existence of files outside of its sandbox. This issue was addressed through additional sandbox checks.
Credit: Xiaokuan Zhang Yinqian Zhang The Ohio State UniversityXueqiang Wang XiaoFeng Wang Indiana University Bloomington Xiaolong Bai Tsinghua University product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS | <11 | 11 |
Apple iPhone OS | <11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The severity of CVE-2017-13877 is medium with a severity value of 3.3.
iOS before version 11 is affected by CVE-2017-13877.
CVE-2017-13877 allows attackers to determine whether arbitrary files exist via a crafted app using the "Sandbox Profiles" component.
Update your iOS to version 11 or later to fix CVE-2017-13877.
You can find more information about CVE-2017-13877 on the Apple support page: https://support.apple.com/HT208112