First published: Sun Apr 02 2017(Updated: )
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "FinderKit" component. It allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging unexpected permission changes during an iCloud Sharing Send Link action.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
macOS Yosemite | <=10.12.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-2429 has been classified as a high-severity vulnerability due to its potential to allow unauthorized access.
To fix CVE-2017-2429, update your macOS to version 10.12.4 or later.
CVE-2017-2429 affects macOS versions prior to 10.12.4.
Yes, CVE-2017-2429 can be exploited by remote attackers under specific circumstances.
CVE-2017-2429 involves the FinderKit component of macOS.