CVE-2017-13786: Apple Mac OS X
Medium severity, CVSS 4.6. EPSS: 0.3% chance of exploitation in the next 30 days.
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "APFS" component. It does not properly restrict the DMA mapping time of FileVault decryption buffers, which allows attackers to read cleartext APFS data via a crafted Thunderbolt adapter.
Affected products
- Apple Mac OS X: up to and including 10.13.0
Published 2017-11-13. Last modified 2026-06-17.