First published: Mon Sep 25 2017(Updated: )
An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the "Mail" component. It allows remote attackers to bypass an intended off value of the "Load remote content in messages" setting, and consequently discover an e-mail recipient's IP address, via an HTML email message.
Credit: product-security@apple.com John Whitehead The New York Times
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mac OS X | <=10.12.6 | |
Apple macOS High Sierra | <10.13 | 10.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID for this issue is CVE-2017-7141.
macOS before 10.13 is affected by this vulnerability.
The severity of CVE-2017-7141 is medium, with a severity value of 5.3.
Attackers can bypass the 'Load remote content in messages' setting in Apple Mail, allowing them to discover an email recipient's IP address.
To fix this vulnerability, update to macOS 10.13 or later and apply the necessary security patches.