PatchSiren

PatchSiren cyber security CVE debrief

CVE-2016-7666 Apple CVE debrief

CVE-2016-7666 is an Apple Transporter information-disclosure issue affecting versions before 1.9.2. NVD says the flaw is in the iTMSTransporter component and can leak sensitive information when a crafted EPUB is processed. The published CVSS score is 5.5 (Medium), reflecting local access with user interaction and confidentiality impact only.

Vendor
Apple
Product
Transporter
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2017-02-20
Original CVE updated
2026-05-13
Advisory published
2017-02-20
Advisory updated
2026-05-13

Who should care

Apple Transporter users, build/release engineers, IT administrators, and developers who rely on iTMSTransporter, especially on systems still running Transporter 1.9.1 or earlier.

Technical summary

NVD classifies the issue as CWE-200 and maps it to Transporter versions up to 1.9.1. The CVSS 3.0 vector is AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N, which indicates a local attack path requiring user interaction and resulting in high confidentiality impact without integrity or availability impact. The vulnerable component is iTMSTransporter, and the triggering condition is a crafted EPUB.

Defensive priority

Medium priority for any environment that still uses Apple Transporter 1.9.1 or earlier. The issue is not remote-code-execution and does not affect integrity or availability, but it can expose sensitive data, so upgrades should be prioritized where Transporter is installed and used with untrusted EPUB content.

Recommended defensive actions

  • Upgrade Apple Transporter to 1.9.2 or later.
  • Inventory systems and build pipelines to find installed Transporter versions at 1.9.1 or below.
  • Limit exposure to untrusted EPUB inputs in workflows that invoke iTMSTransporter.
  • Review Apple's support advisory for any vendor-specific remediation guidance and deployment notes.

Evidence notes

This debrief is based on the supplied CVE description and NVD record. The corpus states that Apple Transporter before 1.9.2 is affected, the issue is in iTMSTransporter, and sensitive information can be obtained via a crafted EPUB. NVD also provides the CVSS 3.0 vector AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N and CWE-200 classification. An Apple support advisory and a third-party bulletin are referenced by NVD, but their full contents were not included in the supplied corpus.

Sources and references

Verified primary and authoritative sources

  • CVE-2016-7666 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2016-7666

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2016-7666 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2016-7666

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.