PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-2360 Apple CVE debrief

CVE-2017-2360 is a high-severity Apple kernel use-after-free disclosed on 2017-02-20. According to the NVD record, a crafted app could trigger the flaw and lead to arbitrary code execution in a privileged context or a denial of service. Apple listed fixes for iOS, macOS, tvOS, and watchOS in the vendor advisories referenced by NVD.

Vendor
Apple
Product
Unknown
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2017-02-20
Original CVE updated
2026-05-13
Advisory published
2017-02-20
Advisory updated
2026-05-13

Who should care

Apple device fleet administrators, MDM and endpoint security teams, and users or organizations running affected iOS, macOS, tvOS, or watchOS versions should prioritize this issue.

Technical summary

The NVD record classifies the weakness as CWE-416 (use-after-free) with CVSS 3.0 vector AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. The affected versions listed in the record are iOS before 10.2.1, macOS before 10.12.3, tvOS before 10.1.1, and watchOS before 3.1.3. The flaw is in the Kernel component, and NVD states that a crafted app may trigger privileged code execution or denial of service.

Defensive priority

High

Recommended defensive actions

  • Upgrade iOS devices to 10.2.1 or later.
  • Upgrade macOS systems to 10.12.3 or later.
  • Upgrade tvOS devices to 10.1.1 or later.
  • Upgrade watchOS devices to 3.1.3 or later.
  • Use MDM or compliance tooling to identify and remediate devices below the fixed versions.
  • Review app installation and distribution controls on affected fleets until patching is complete.

Evidence notes

This debrief is based on the supplied CVE record and NVD metadata. The published CVE date is 2017-02-20, and the later modified date is not treated as the disclosure date. NVD lists CWE-416 and the CVSS 3.0 vector AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, and it references Apple vendor advisories for the fixed version thresholds.

Sources and references

Verified primary and authoritative sources

  • CVE-2017-2360 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2017-2360

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2017-2360 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2017-2360

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.