CVE-2017-2360: Use After Free
Kernel. A use after free issue was addressed through improved memory management.
Other sources
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS before 10.1.1 is affected. watchOS before 3.1.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (use-after-free) via a crafted app.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 10.2.1
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2017-2360?
CVE-2017-2360 has been categorized with a severity rating that signifies a high risk of exploitation in affected Apple products.
Which Apple products are affected by CVE-2017-2360?
CVE-2017-2360 affects iOS versions before 10.2.1, macOS versions before 10.12.3, tvOS before 10.1.1, and watchOS before 3.1.3.
How do I fix CVE-2017-2360?
To fix CVE-2017-2360, update your device to the latest version of the affected software, specifically iOS 10.2.1 or later, macOS 10.12.3 or later, tvOS 10.1.1 or later, or watchOS 3.1.3 or later.
What type of vulnerability is CVE-2017-2360?
CVE-2017-2360 is classified as a use after free vulnerability, which occurs when memory is improperly freed and subsequently accessed.
Can CVE-2017-2360 affect my device's security?
Yes, CVE-2017-2360 can potentially allow an attacker to execute arbitrary code, thereby compromising the device's security.