First published: Tue Sep 19 2017(Updated: )
Security. A permission checking issue existed in the handling of an app's Keychain data. This issue was addressed with improved permission checking.
Credit: an anonymous researcher product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS | <11 | 11 |
Apple iPhone OS | <=10.3.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2017-7146 is a vulnerability that affects certain Apple products, specifically iOS versions before 11.
CVE-2017-7146 allows attackers to track users across installations of a crafted app that leverages Keychain data mishandling.
iOS versions before 11 are affected by CVE-2017-7146.
CVE-2017-7146 has a severity rating of medium (5.3).
Users can update their Apple devices to iOS 11 or later to mitigate the impact of CVE-2017-7146.