This issue was addressed with a new entitlement. This issue is fixed in macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra, iOS 12.4, tvOS 12.4. A local user may be able to read a persistent account identifier.
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
Link | Tags |
---|---|
https://support.apple.com/en-us/HT210348 | vendor advisory |
https://support.apple.com/en-us/HT210346 | vendor advisory |
https://support.apple.com/en-us/HT210351 | vendor advisory |