An issue was discovered in certain Apple products. Safari before 10.1 is affected. The issue involves the "Safari Login AutoFill" component. It allows local users to obtain access to locked keychain items via unspecified vectors.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1038137 | vdb entry |
https://support.apple.com/HT207600 | vendor advisory |
http://www.securityfocus.com/bid/97136 | vdb entry third party advisory |