iWork PDF Password Bypass in Apple Products
CVE-2017-2391
5.3MEDIUM
What is CVE-2017-2391?
An issue has been identified in certain versions of Apple's iWork suite, affecting both macOS and iOS. This vulnerability enables unauthorized users to bypass the PDF password protection due to the use of 40-bit RC4 encryption in the Export component. Specific affected versions include Pages, Numbers, and Keynote, with various thresholds across macOS and iOS platforms. This security gap raises concerns over data confidentiality and integrity, prompting users to upgrade to secure versions.