First published: Fri Jun 01 2018(Updated: )
Mail. An issue existed in the handling of encrypted Mail. This issue was addressed with improved isolation of MIME in Mail.
Credit: Damian Poddebniak MChristian Dresen MJens Müller Ruhr University BochumFabian Ising MSebastian Schinzel MSimon Friedberger KU LeuvenJuraj Somorovsky Ruhr University BochumJörg Schwenk Ruhr University Bochum product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPhone OS | <11.4 | |
Apple Mac OS X | <10.13.5 | |
Apple macOS High Sierra | <10.13.5 | 10.13.5 |
Apple Sierra | ||
Apple El Capitan |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID for this issue is CVE-2018-4227.
The severity level of CVE-2018-4227 is high with a score of 7.5.
iOS before 11.4 and macOS before 10.13.5 are affected by this vulnerability.
An attacker can exploit this vulnerability by reading the cleartext content of S/MIME encrypted messages via direct exfiltration.
Yes, the issue has been addressed with improved isolation of S/MIME encrypted messages in the affected Apple products.