CVE-2017-13905: Apple iPhone OS
High severity, CVSS 8.1. EPSS: 0.9% chance of exploitation in the next 30 days.
A race condition was addressed with additional validation. This issue is fixed in tvOS 11.2, iOS 11.2, macOS High Sierra 10.13.2, Security Update 2017-002 Sierra, and Security Update 2017-005 El Capitan, watchOS 4.2. An application may be able to gain elevated privileges.
Affected products
- Apple iPhone OS: before 11.2 (fixed in 11.2)
- Apple Mac OS X: from 10.11, before 10.11.6 (fixed in 10.11.6); from 10.12, before 10.12.6 (fixed in 10.12.6); version 10.11.6 only; version 10.12.6 only
- Apple macOS: before 10.13.2 (fixed in 10.13.2)
- Apple tvOS: before 11.2 (fixed in 11.2)
- Apple watchOS: before 4.2 (fixed in 4.2)
Published 2021-12-23. Last modified 2026-06-17.