The issue was addressed with additional permissions checks. This issue is fixed in macOS Ventura 13.6.1. An attacker may be able to access passkeys without authentication.
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Link | Tags |
---|---|
https://support.apple.com/en-us/HT213985 | release notes vendor advisory |
https://support.apple.com/kb/HT213927 | |
https://support.apple.com/kb/HT213940 | |
https://support.apple.com/kb/HT213938 | |
https://support.apple.com/kb/HT213985 | release notes vendor advisory |
http://seclists.org/fulldisclosure/2023/Oct/26 | third party advisory mailing list |