vendor:
iCloud Desktop Client
by:
Yakir Wizman, Victor Minin, Alexander Korznikov
N/A
CVSS
N/A
Local Credentials Disclosure
CWE
Product Name: iCloud Desktop Client
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE: cpe:2.3:a:apple:icloud_desktop_client:5.2.1.0:*:*:*:*:*:*:*
Platforms Tested: Windows
2016
Apple iCloud Desktop Client v5.2.1.0 Local Credentials Disclosure After Sign Out Exploit
Apple iCloud Desktop Client v5.2.1.0 is vulnerable to local credentials disclosure after the user is logged out. It seems that iCloud does not store the supplied credentials while the user is logged in, but after sign out the supplied username and password are stored in a plaintext format in memory process. A potential attacker could reveal the supplied username and password in order to gain access to iCloud account.