An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. The issue involves the "Mail" component. It allows remote attackers to read the cleartext content of S/MIME encrypted messages via direct exfiltration.
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Link | Tags |
---|---|
https://efail.de/#cve | third party advisory exploit |
http://www.securitytracker.com/id/1041027 | vdb entry third party advisory |
http://www.securityfocus.com/bid/104897 | vdb entry third party advisory |
https://support.apple.com/HT208848 | vendor advisory |
https://support.apple.com/HT208849 | vendor advisory |