An issue was discovered in certain Apple products. iCloud before 6.2 on Windows is affected. iTunes before 12.6 on Windows is affected. The issue involves cleartext client-certificate transmission in the APNs Server component. It allows man-in-the-middle attackers to track users via correlation with this certificate.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Icloud | Apple | * | 6.1.1 (including) |
Itunes | Apple | * | 12.5.5.5 (including) |