CVE-2016-4644: Infoleak
In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, a downgrade issue existed with HTTP authentication credentials saved in Keychain. This issue was addressed by storing the authentication types with the credentials.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-4644?
The severity of CVE-2016-4644 is medium (6.5 out of 10).
What is the impact of CVE-2016-4644?
CVE-2016-4644 allows an attacker to downgrade HTTP authentication credentials saved in Keychain.
Which Apple devices are affected by CVE-2016-4644?
CVE-2016-4644 affects Apple Apple TV (up to version 9.2.2), Apple iPhone OS (up to version 9.3.3), and Apple Mac OS (up to version 10.11.6).
How can I fix CVE-2016-4644?
To fix CVE-2016-4644, update your iOS device to version 9.3.3 or later, update your Apple TV to version 9.2.2 or later, and update your Mac OS to version 10.11.6 or later.
Where can I find more information about CVE-2016-4644?
You can find more information about CVE-2016-4644 on the Apple support website: [link](https://support.apple.com/HT206902).