First published: Mon Feb 20 2017(Updated: )
An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. The issue involves the "CFNetwork Proxies" component, which allows man-in-the-middle attackers to spoof a proxy password authentication requirement and obtain sensitive information.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
iPhone OS | <10.1 | |
Apple iOS and macOS | <10.12.1 | |
tvOS | <10.0.1 | |
<10.1 | ||
<10.12.1 | ||
<10.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-7579 has a medium severity rating due to its potential for man-in-the-middle attacks.
To mitigate CVE-2016-7579, users should update their iOS to 10.1, macOS to 10.12.1, or tvOS to 10.0.1 or later.
CVE-2016-7579 affects iOS versions prior to 10.1, macOS versions prior to 10.12.1, and tvOS versions prior to 10.0.1.
CVE-2016-7579 allows man-in-the-middle attackers to spoof proxy authentication requirements.
There are no specific workarounds for CVE-2016-7579 other than upgrading to the recommended software versions.