The Security - Keychain component in Apple OS X before 10.9.4 does not properly implement keystroke observers, which allows physically proximate attackers to bypass the screen-lock protection mechanism, and enter characters into an arbitrary window under the lock window, via keyboard input.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://support.apple.com/kb/HT6296 | |
http://www.securitytracker.com/id/1030505 | vdb entry |
http://archives.neohapsis.com/archives/bugtraq/2014-06/0172.html | vendor advisory |