VYPR
Unrated severityNVD Advisory· Published Dec 23, 2021· Updated Aug 5, 2024

CVE-2017-13892

CVE-2017-13892

Description

An issue existed in the handling of Contact sharing. This issue was addressed with improved handling of user information. This issue is fixed in macOS High Sierra 10.13.2, Security Update 2017-002 Sierra, and Security Update 2017-005 El Capitan. Sharing contact information may lead to unexpected data sharing.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Sharing contact information in macOS could lead to unexpected data sharing due to improper handling of user data.

Vulnerability

An issue existed in the handling of Contact sharing on macOS High Sierra 10.13.1 and earlier, Sierra, and El Capitan. The vulnerability allowed sharing contact information in a way that could lead to unexpected data sharing. The issue was addressed with improved handling of user information. The fix is included in macOS High Sierra 10.13.2, Security Update 2017-002 Sierra, and Security Update 2017-005 El Capitan [1].

Exploitation

An attacker would need to convince a user to share their contact information through an app or service that leverages the Contacts framework. The vulnerability involves a failure to properly restrict the scope of shared data, potentially exposing more information than intended. No technical details about the exact exploitation sequence are disclosed in the available reference [1].

Impact

Successful exploitation could result in unintended disclosure of contact information to third parties, violating the user's expectation of privacy. The impact is limited to information disclosure (confidentiality) and does not affect the integrity or availability of the system [1].

Mitigation

Apply the software updates provided by Apple: macOS High Sierra 10.13.2, Security Update 2017-002 Sierra, or Security Update 2017-005 El Capitan, all released on December 6, 2017 [1]. No workaround is documented; users should update to the patched versions.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.