CVE-2017-2534 — Apple MAC OS X vulnerability
14 documents4 sources
Severity
8.6HIGHNVD
EPSS
0.2%
top 55.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 22
Latest updateMay 13
Description
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Speech Framework" component. It allows attackers to conduct sandbox-escape attacks via a crafted app.
CVSS vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HExploitability: 1.8 | Impact: 6.0
Affected Packages2 packages
🔴Vulnerability Details
1📋Vendor Advisories
1Apple▶
CVE-2017-2534: macOS Sierra 10.12.5, Security Update 2017-002 El Capitan, and Security Update 2017-002 Yosemite↗2017-05-15
💬Community
11Bugzilla▶
CVE-2017-7809 Mozilla: Use-after-free while deleting attached editor DOM node (MFSA 2017-19)↗2017-08-09
Bugzilla
▶
Bugzilla
▶