Skip to main content

Apple Releases Security Update for iWork

Apple has released a security update for MacOS 10.12 (and later) and iOS 10.0 (and later) to address a vulnerability in iWork that allows a remote attacker to obtain sensitive information. 
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

Apple has released a security update for MacOS 10.12 (and later) and iOS 10.0 (and later) to address a vulnerability in iWork that allows a remote attacker to obtain sensitive information. 

Affected platforms

The following platforms are known to be affected:

Threat details

The vulnerability allows the contents of password protected PDFs, exported from iWork, to be exposed. The security update addresses the weak encryption algorithm used by the application, implementing AES-128 bit encryption standard to improve the previously used 40-bit RC4 .

CVE-2017-2391


Remediation steps

Type Step
Review Apple's security update for the vulnerability and apply the necessary update.

CVE Vulnerabilities

Last edited: 17 February 2020 11:26 am