VYPR
Unrated severityNVD Advisory· Published Dec 23, 2021· Updated Aug 5, 2024

CVE-2017-13909

CVE-2017-13909

Description

An issue existed in the storage of sensitive tokens. This issue was addressed by placing the tokens in Keychain. This issue is fixed in macOS High Sierra 10.13. A local attacker may gain access to iCloud authentication tokens.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

iCloud authentication tokens were stored insecurely on macOS, allowing local attacker access. Fixed in macOS High Sierra 10.13.

Vulnerability

An issue existed in the storage of sensitive iCloud authentication tokens on macOS. Prior to macOS High Sierra 10.13, these tokens were not placed in the system Keychain, leaving them accessible to a local attacker. This issue is fixed in macOS High Sierra 10.13, released September 25, 2017 [1].

Exploitation

A local attacker needs access to the affected macOS system (OS X Mountain Lion 10.8 and later) to exploit this vulnerability. The attacker could gain access to iCloud authentication tokens by reading the insecure storage location. No additional authentication or user interaction beyond local access is required [1].

Impact

A successful attacker could obtain the victim's iCloud authentication tokens, potentially allowing access to iCloud services and data linked to the Apple ID. The attack leads to credential disclosure with local access [1].

Mitigation

The vulnerability is patched in macOS High Sierra 10.13, released on September 25, 2017 [1]. Users should update to macOS High Sierra 10.13 or later. No workaround is documented. Apple does not disclose, discuss, or confirm security issues until patches are available [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.