PatchSiren cyber security CVE debrief
CVE-2017-2360 Apple CVE debrief
CVE-2017-2360 is a high-severity Apple kernel use-after-free disclosed on 2017-02-20. According to the NVD record, a crafted app could trigger the flaw and lead to arbitrary code execution in a privileged context or a denial of service. Apple listed fixes for iOS, macOS, tvOS, and watchOS in the vendor advisories referenced by NVD.
- Vendor
- Apple
- Product
- Unknown
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-20
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-20
- Advisory updated
- 2026-05-13
Who should care
Apple device fleet administrators, MDM and endpoint security teams, and users or organizations running affected iOS, macOS, tvOS, or watchOS versions should prioritize this issue.
Technical summary
The NVD record classifies the weakness as CWE-416 (use-after-free) with CVSS 3.0 vector AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. The affected versions listed in the record are iOS before 10.2.1, macOS before 10.12.3, tvOS before 10.1.1, and watchOS before 3.1.3. The flaw is in the Kernel component, and NVD states that a crafted app may trigger privileged code execution or denial of service.
Defensive priority
High
Recommended defensive actions
- Upgrade iOS devices to 10.2.1 or later.
- Upgrade macOS systems to 10.12.3 or later.
- Upgrade tvOS devices to 10.1.1 or later.
- Upgrade watchOS devices to 3.1.3 or later.
- Use MDM or compliance tooling to identify and remediate devices below the fixed versions.
- Review app installation and distribution controls on affected fleets until patching is complete.
Evidence notes
This debrief is based on the supplied CVE record and NVD metadata. The published CVE date is 2017-02-20, and the later modified date is not treated as the disclosure date. NVD lists CWE-416 and the CVSS 3.0 vector AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, and it references Apple vendor advisories for the fixed version thresholds.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-2360 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-2360
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-2360 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-2360
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://support.apple.com/HT207482
[email protected] - Vendor Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://support.apple.com/HT207483
[email protected] - Vendor Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://support.apple.com/HT207485
[email protected] - Vendor Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://support.apple.com/HT207487
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.