An issue was discovered in certain Apple products. iOS before 11 is affected. tvOS before 11 is affected. The issue involves the "Wi-Fi" component. It might allow remote attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via crafted Wi-Fi traffic that leverages a race condition.
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/100924 | third party advisory vdb entry |
http://www.securitytracker.com/id/1039385 | third party advisory vdb entry |
https://support.apple.com/HT208113 | vendor advisory |
https://support.apple.com/HT208112 | vendor advisory |
https://www.exploit-db.com/exploits/42996/ | third party advisory vdb entry exploit |
https://bugs.chromium.org/p/project-zero/issues/detail?id=1317 | exploit mitigation third party advisory issue tracking technical description |