An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the iTunes Store component. It allows man-in-the-middle attackers to modify the client-server data stream to iTunes sandbox web services by leveraging use of cleartext HTTP.
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Iphone_os | Apple | * | 10.2.1 (including) |