An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "Kernel" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1038484 | vdb entry third party advisory |
https://support.apple.com/HT207797 | vendor advisory |
https://support.apple.com/HT207800 | vendor advisory |
http://www.securityfocus.com/bid/98468 | vdb entry third party advisory |
https://www.exploit-db.com/exploits/42054/ | exploit vdb entry third party advisory |
https://support.apple.com/HT207798 | vendor advisory |
https://support.apple.com/HT207801 | vendor advisory |