CVE-2017-13847Disclosure(apple / iphone_os)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple iphone_os systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. The issue involves the "IOKit" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • iphone_os
  • mac_os_x

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-05-12); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
iphone_osmac_os_x

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-12: 1Mentions · 2026-05-20: 1Patch / Workaround · 2026-05-20: 1Technical Details · 2026-05-12: 105-1205-20
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-121
Disclosure1
2026-05-201
Patch1
Full discourse2 posts
  • GanaSec@ganaseclabs
    Patch

    The same bug class Google Project Zero's Ian Beer reported in 2017 as CVE-2017-13847. Apple patched it then. The fix regressed. Nine years later, the ghost came back. Read here : https://ganasec.com/blog/the-2017-ghost-in-the-time-machine-hunting-iotimesyncfamily Patched across iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. #GanaSec

    Post summary

    The post highlights that a CVE-2017-13847‑type bug reappeared in Apple products after a patch regression, noting that the issue is now patched across iOS, iPadOS, macOS, tvOS, visionOS, and watchOS.

    08126176.2K
    37 followersView on X
  • Bountyy Oy@BountyyOy
    Disclosure

    First blog is up. The 2017 Ghost. CVE-2026-28969. Kernel UAF in IOTimeSyncClockManagerUserClient. Same root cause as CVE-2017-13847. Patch got lost in a refactor and the bug came back. Eight years later. http://bountyy.fi/blog/the-2017-ghost #cve #apple #bugbounty

    Post summary

    A blog post announces the resurfacing of Apple’s 2017 Ghost kernel UAF (CVE-2026-28969), noting that a previously applied patch was lost during a refactor.

    0000054
    3 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSappleiphone_os---
OSapplemac_os_x---

Explore more