First published: Tue Sep 19 2017(Updated: )
APNs. A privacy issue existed in the use of client certificates. This issue was addressed through a revised protocol.
Credit: FURIOUSMAC Team United States Naval Academy product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS | <11 | 11 |
Apple iPhone OS | <11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The severity of CVE-2017-13863 is medium with a CVSS score of 5.9.
CVE-2017-13863 affects certain Apple products running iOS before version 11.
The vulnerability in CVE-2017-13863 is a privacy issue related to the use of client certificates in the APNs component of iOS.
Man-in-the-middle attackers can exploit CVE-2017-13863 to track users by leveraging the transmission of client certificates.
To fix the CVE-2017-13863 vulnerability, you should update to iOS 11 or later, as it addresses the issue.