First published: Mon Oct 23 2017(Updated: )
An issue was discovered in certain Apple products. macOS before 10.13 Supplemental Update is affected. The issue involves the "StorageKit" component. It allows attackers to discover passwords for APFS encrypted volumes by reading Disk Utility hints, because the stored hint value was accidentally set to the password itself, not the entered hint value.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS and macOS | <=10.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7149 has a high severity rating due to its potential to expose sensitive encrypted volume passwords.
To fix CVE-2017-7149, update to macOS version 10.13 Supplemental Update or later.
CVE-2017-7149 affects macOS versions prior to 10.13 Supplemental Update, specifically the StorageKit component.
Yes, CVE-2017-7149 can allow attackers to gain unauthorized access to APFS encrypted volumes by revealing stored password hints.
Any user running macOS before the 10.13 Supplemental Update is vulnerable to CVE-2017-7149.