Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Alastair Houghton

#27414of 53,633
9.3Total CVSS
Vulnerabilities · 1
PT-2017-3312
9.3
2017-11-01
Apple · Apple Macos · CVE-2017-13838
**Name of the Vulnerable Software and Affected Versions** macOS versions prior to 10.13.1 **Description** The issue involves the `Sandbox` component and allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app. This is caused by a buffer overflow in memory, which can be exploited by a remote attacker to achieve the aforementioned effects. **Recommendations** For macOS versions prior to 10.13.1, update to version 10.13.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of the `Sandbox` component until a patch is applied.