Vulnerability: Cleartext APFS Data Disclosure via Crafted Thunderbolt Adapter

Vulnerability: Cleartext APFS Data Disclosure via Crafted Thunderbolt Adapter

CVE-2017-13786 · LOW Severity

AV:L/AC:L/AU:N/C:P/I:N/A:N

An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "APFS" component. It does not properly restrict the DMA mapping time of FileVault decryption buffers, which allows attackers to read cleartext APFS data via a crafted Thunderbolt adapter.

Learn more about our Cis Benchmark Audit For Apple Macos.