First published: Sat Oct 18 2014(Updated: )
Race condition in LoginWindow in Apple OS X before 10.10 allows physically proximate attackers to obtain access by leveraging an unattended workstation on which screen locking had been attempted.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS and macOS | <=10.9.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-4438 is classified as a medium severity vulnerability due to its potential to allow unauthorized access to unattended workstations.
To mitigate CVE-2014-4438, ensure that your system is updated to OS X version 10.10 or later, which addresses this race condition.
CVE-2014-4438 affects users of Apple OS X versions prior to 10.10 who may leave their workstations unattended.
CVE-2014-4438 exploits a race condition in the LoginWindow, which can allow attackers physical access to bypass screen locking.
CVE-2014-4438 can facilitate unauthorized access attacks when a user leaves their workstation unattended.