CVE-2017-11122: Apple iPhone OS

High severity, CVSS 7.5. EPSS: 1.8% chance of exploitation in the next 30 days.

On Broadcom BCM4355C0 Wi-Fi chips 9.44.78.27.0.1.56, an attacker can trigger an information leak due to insufficient length validation, related to ICMPv6 router advertisement offloading.

Affected products

  • Apple iPhone OS: up to and including 10.3.3
  • Apple tvOS: up to and including 10.2.2
  • Broadcom BCM4355C0 Firmware: up to and including 9.44.78.27.0.1.56

Published 2017-10-04. Last modified 2026-06-17.