CVE-2017-7150
published 2017-10-23CVE-2017-7150: An issue was discovered in certain Apple products. macOS before 10.13 Supplemental Update is affected. The issue involves the "Security" component. It allows…
PriorityP423medium5.5CVSS 3.0
AVLACLPRLUINSUCHINAN
EPSS
0.33%
25.4th percentile
An issue was discovered in certain Apple products. macOS before 10.13 Supplemental Update is affected. The issue involves the "Security" component. It allows attackers to bypass the keychain access prompt, and consequently extract passwords, via a synthetic click.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | <= 10.12.6 | — |
| apple | macos_high_sierra_10.13.1_security_update_2017-001_sierra_and_security_update_20 | — | — |
| apple | macos_high_sierra_10.13_supplemental_update | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3pr4-c94w-58x7: An issue was discovered in certain Apple products
ghsa_unreviewed·2022-05-13
CVE-2017-7150 [MEDIUM] CWE-521 GHSA-3pr4-c94w-58x7: An issue was discovered in certain Apple products
An issue was discovered in certain Apple products. macOS before 10.13 Supplemental Update is affected. The issue involves the "Security" component. It allows attackers to bypass the keychain access prompt, and consequently extract passwords, via a synthetic click.
Apple
CVE-2017-7150: macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, and Security Update 2017-004 El Capitan
vendor_apple·2017-10-31·CVSS 5.5
CVE-2017-7150 [MEDIUM] CVE-2017-7150: macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, and Security Update 2017-004 El Capitan
Apple Security Update: About the security content of macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, and Security Update 2017-004 El Capitan
Product: macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, and Security Update 2017-004 El Capitan
CVE: CVE-2017-7150
Component: Security
Impact: A malicious application can extract keychain passwords
Description: A method existed for applications to bypass the keychain access prompt with a synthetic click. This was addressed by requiring the user password when prompting for keychain access.
Apple
CVE-2017-7150: macOS High Sierra 10.13 Supplemental Update
vendor_apple·2017-10-05·CVSS 5.5
CVE-2017-7150 [MEDIUM] CVE-2017-7150: macOS High Sierra 10.13 Supplemental Update
Apple Security Update: About the security content of macOS High Sierra 10.13 Supplemental Update
Product: macOS High Sierra 10.13 Supplemental Update
CVE: CVE-2017-7150
Component: Security
Impact: A malicious application can extract keychain passwords
Description: A method existed for applications to bypass the keychain access prompt with a synthetic click. This was addressed by requiring the user password when prompting for keychain access.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-10-23
Published