CVE-2017-13909

MEDIUM

macOS High Sierra <10.13 - Info Disclosure

Title source: llm
STIX 2.1

Description

An issue existed in the storage of sensitive tokens. This issue was addressed by placing the tokens in Keychain. This issue is fixed in macOS High Sierra 10.13. A local attacker may gain access to iCloud authentication tokens.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT208144

Scores

CVSS v3 5.5
EPSS 0.0023
EPSS Percentile 13.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-922
Status published
Products (1)
apple/mac_os_x 10.0 - 10.13
Published Dec 23, 2021
Tracked Since Feb 18, 2026