[CVE-2023-38596] Apple macOS 与 iOS 中 ATS 的问题
blog.trailofbits.com | 漏洞 | CVE-2023-38596 | #macos | #ios | #apple | #tls | #vulnerability-disclosure | #ats | #cve-2023-38596 | #mitm
摘要
Trail of Bits 公开披露 CVE-2023-38596:Apple 的 App Transport Security(ATS)未对 IP 地址和 .local 主机名连接强制 TLS 加密,影响 iOS 17、macOS 14、watchOS 10 之前版本,应用可能遭受中间人攻击或信息泄露;Apple 已在 2023 年 9 月的公告中确认修复。
- 发布时间
- 收录时间
Skip to content