An issue was discovered in certain Apple products. iCloud before 6.2 on Windows is affected. iTunes before 12.6 on Windows is affected. The issue involves cleartext client-certificate transmission in the "APNs Server" component. It allows man-in-the-middle attackers to track users via correlation with this certificate.
2017-04-02T01:59:00.450
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 3.1 (LOW)
AV:N/AC:M/Au:S/C:P/I:N/A:N
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | apple | icloud | ≤ 6.1.1 | Yes |
Application | apple | itunes | ≤ 12.5.5.5 | Yes |