First published: Fri Jan 30 2015(Updated: )
The App Store process in CommerceKit Framework in Apple OS X before 10.10.2 places Apple ID credentials in App Store logs, which allows local users to obtain sensitive information by reading a file.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
macOS Yosemite | <=10.10.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-4499 is given a medium severity rating due to the exposure of sensitive Apple ID credentials in logs.
To fix CVE-2014-4499, update your macOS to version 10.10.2 or later where the vulnerability is patched.
CVE-2014-4499 affects users running macOS Yosemite versions prior to 10.10.2.
CVE-2014-4499 exposes Apple ID credentials through the App Store process logs.
Yes, local users can exploit CVE-2014-4499 to read sensitive Apple ID information from log files.