First published: Sun Sep 25 2016(Updated: )
The SecKeyDeriveFromPassword function in Apple OS X before 10.12 does not use the CF_RETURNS_RETAINED keyword, which allows attackers to obtain sensitive information from process memory by triggering key derivation.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS and macOS | <=10.11.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4752 is rated as high severity due to the potential for sensitive information leakage from process memory.
To fix CVE-2016-4752, update your Apple OS X to version 10.12 or later, which includes the necessary security patches.
CVE-2016-4752 affects Apple OS X versions prior to 10.12, including all versions up to 10.11.6.
CVE-2016-4752 can lead to unauthorized access to sensitive information stored in memory, compromising system security.
CVE-2016-4752 specifically impacts macOS Yosemite and may not be applicable to other Apple device operating systems.