In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, a downgrade issue existed with HTTP authentication credentials saved in Keychain. This issue was addressed by storing the authentication types with the credentials.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://support.apple.com/HT206902 | vendor advisory |
https://support.apple.com/HT206903 | vendor advisory |
https://support.apple.com/HT206905 | vendor advisory |