CVE-2017-13892: Apple Mac OS X

High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.

An issue existed in the handling of Contact sharing. This issue was addressed with improved handling of user information. This issue is fixed in macOS High Sierra 10.13.2, Security Update 2017-002 Sierra, and Security Update 2017-005 El Capitan. Sharing contact information may lead to unexpected data sharing.

Affected products

  • Apple Mac OS X: from 10.11, before 10.11.6 (fixed in 10.11.6); from 10.12, before 10.12.6 (fixed in 10.12.6); version 10.11.6 only; version 10.12.6 only
  • Apple macOS: before 10.13.2 (fixed in 10.13.2)

Published 2021-12-23. Last modified 2026-06-17.