CVE-2017-2425: Apple Mac OS X

High severity, CVSS 7.8. EPSS: 1.2% chance of exploitation in the next 30 days.

An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "SecurityFoundation" component. A double free vulnerability allows remote attackers to execute arbitrary code via a crafted certificate.

Affected products

  • Apple Mac OS X: up to and including 10.12.3

Published 2017-04-02. Last modified 2026-06-17.