{"api_version":"1","generated_at":"2026-07-23T04:24:22+00:00","cve":"CVE-2017-7150","urls":{"html":"https://cve.report/CVE-2017-7150","api":"https://cve.report/api/cve/CVE-2017-7150.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-7150","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-7150"},"summary":{"title":"CVE-2017-7150","description":"An issue was discovered in certain Apple products. macOS before 10.13 Supplemental Update is affected. The issue involves the \"Security\" component. It allows attackers to bypass the keychain access prompt, and consequently extract passwords, via a synthetic click.","state":"PUBLIC","assigner":"product-security@apple.com","published_at":"2017-10-23 01:29:00","updated_at":"2019-10-03 00:03:00"},"problem_types":["CWE-521"],"metrics":[],"references":[{"url":"http://www.securityfocus.com/bid/101177","name":"101177","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"Apple macOS CVE-2017-7150 Security Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://support.apple.com/HT208165","name":"https://support.apple.com/HT208165","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"About the security content of macOS High Sierra 10.13 Supplemental Update - Apple Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1039430","name":"1039430","refsource":"SECTRACK","tags":["Third Party Advisory","VDB Entry"],"title":"Apple macOS/OS X Unspecified Flaw Lets Local Users View Keychain Passwords - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-7150","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-7150","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"7150","vulnerable":"1","versionEndIncluding":"10.12.6","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"product-security@apple.com","ID":"CVE-2017-7150","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An issue was discovered in certain Apple products. macOS before 10.13 Supplemental Update is affected. The issue involves the \"Security\" component. It allows attackers to bypass the keychain access prompt, and consequently extract passwords, via a synthetic click."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://support.apple.com/HT208165","refsource":"CONFIRM","url":"https://support.apple.com/HT208165"},{"name":"1039430","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1039430"},{"name":"101177","refsource":"BID","url":"http://www.securityfocus.com/bid/101177"}]}},"nvd":{"publishedDate":"2017-10-23 01:29:00","lastModifiedDate":"2019-10-03 00:03:00","problem_types":["CWE-521"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":1.8,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":2.1},"severity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*","versionEndIncluding":"10.12.6","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"7150","Ordinal":"103845","Title":"CVE-2017-7150","CVE":"CVE-2017-7150","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"7150","Ordinal":"1","NoteData":"An issue was discovered in certain Apple products. macOS before 10.13 Supplemental Update is affected. The issue involves the \"Security\" component. It allows attackers to bypass the keychain access prompt, and consequently extract passwords, via a synthetic click.","Type":"Description","Title":null},{"CveYear":"2017","CveId":"7150","Ordinal":"2","NoteData":"2017-10-22","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"7150","Ordinal":"3","NoteData":"2017-10-23","Type":"Other","Title":"Modified"}]}}}