CVE-2007-4699: High severity Apple iOS and macOS vulnerability
The default configuration of Safari in Apple Mac OS X 10.4 through 10.4.10 adds a private key to the keychain with permissions that allow other applications to access the key without warning the user, which might allow other applications to bypass intended access restrictions.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2007-4699?
CVE-2007-4699 is considered a medium severity vulnerability due to its potential to allow unauthorized access to sensitive cryptographic keys.
How do I fix CVE-2007-4699?
To fix CVE-2007-4699, update your Safari browser and Mac OS X to the latest version available.
What versions of Apple Mac OS X are affected by CVE-2007-4699?
CVE-2007-4699 affects Apple Mac OS X versions 10.4 through 10.4.10.
Can applications exploit CVE-2007-4699 without user consent?
Yes, malicious applications can exploit CVE-2007-4699 to bypass intended access controls without notifying the user.
Is CVE-2007-4699 still a threat today?
CVE-2007-4699 is less of a threat today as it impacts outdated software, but it remains relevant for systems still running those versions.