First published: Fri Oct 09 2015(Updated: )
The Secure Empty Trash feature in Finder in Apple OS X before 10.11 improperly deletes Trash files, which might allow local users to obtain sensitive information by reading storage media, as demonstrated by reading a flash drive.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
macOS Yosemite | <=10.10.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-5901 is considered a moderate severity vulnerability as it allows local users to potentially access sensitive information.
To fix CVE-2015-5901, users should upgrade to OS X version 10.11 or later, where the vulnerability has been addressed.
CVE-2015-5901 affects users of Apple OS X versions prior to 10.11, specifically those using OS X Yosemite or earlier.
CVE-2015-5901 may allow local users to retrieve sensitive files that were supposed to be securely deleted from the Trash.
CVE-2015-5901 is a local vulnerability, meaning it can only be exploited by users with physical access to the affected system.