First published: Fri Jan 11 2019(Updated: )
In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, a downgrade issue existed with HTTP authentication credentials saved in Keychain. This issue was addressed by storing the authentication types with the credentials.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple TV | <9.2.2 | |
iPhone OS | <9.3.3 | |
Apple iOS and macOS | >=10.11.0<10.11.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2016-4644 is medium (6.5 out of 10).
CVE-2016-4644 allows an attacker to downgrade HTTP authentication credentials saved in Keychain.
CVE-2016-4644 affects Apple Apple TV (up to version 9.2.2), Apple iPhone OS (up to version 9.3.3), and Apple Mac OS (up to version 10.11.6).
To fix CVE-2016-4644, update your iOS device to version 9.3.3 or later, update your Apple TV to version 9.2.2 or later, and update your Mac OS to version 10.11.6 or later.
You can find more information about CVE-2016-4644 on the Apple support website: [link](https://support.apple.com/HT206902).