CVE-2017-13909
Description
An issue existed in the storage of sensitive tokens. This issue was addressed by placing the tokens in Keychain. This issue is fixed in macOS High Sierra 10.13. A local attacker may gain access to iCloud authentication tokens.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
iCloud authentication tokens were stored insecurely on macOS, allowing local attacker access. Fixed in macOS High Sierra 10.13.
Vulnerability
An issue existed in the storage of sensitive iCloud authentication tokens on macOS. Prior to macOS High Sierra 10.13, these tokens were not placed in the system Keychain, leaving them accessible to a local attacker. This issue is fixed in macOS High Sierra 10.13, released September 25, 2017 [1].
Exploitation
A local attacker needs access to the affected macOS system (OS X Mountain Lion 10.8 and later) to exploit this vulnerability. The attacker could gain access to iCloud authentication tokens by reading the insecure storage location. No additional authentication or user interaction beyond local access is required [1].
Impact
A successful attacker could obtain the victim's iCloud authentication tokens, potentially allowing access to iCloud services and data linked to the Apple ID. The attack leads to credential disclosure with local access [1].
Mitigation
The vulnerability is patched in macOS High Sierra 10.13, released on September 25, 2017 [1]. Users should update to macOS High Sierra 10.13 or later. No workaround is documented. Apple does not disclose, discuss, or confirm security issues until patches are available [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <10.13
- Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- support.apple.com/en-us/HT208144mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.