First published: Mon Sep 25 2017(Updated: )
An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the "Installer" component. It does not properly restrict an app's entitlements for accessing the FileVault unlock key.
Credit: product-security@apple.com Patrick Wardle Synack
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mac OS X | =10.13.0 | |
Apple macOS High Sierra | <10.13 | 10.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2017-13837 is a vulnerability that affects certain Apple products running macOS before 10.13. It involves the 'Installer' component and allows improper access to the FileVault unlock key.
CVE-2017-13837 affects macOS before version 10.13, allowing apps to access the FileVault unlock key without proper restrictions on entitlements.
CVE-2017-13837 has a severity rating of high, with a CVSS score of 7.5.
To fix CVE-2017-13837, update macOS to version 10.13 or higher, which includes the necessary security patches.
You can find more information about CVE-2017-13837 on the Apple support page: https://support.apple.com/HT208144