This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sonoma 14.7.1, macOS Ventura 13.7.1. A malicious application may be able to leak a user's credentials.
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Link | Tags |
---|---|
https://support.apple.com/en-us/121570 | vendor advisory |
https://support.apple.com/en-us/121568 | vendor advisory |
https://news.ycombinator.com/item?id=43425605 | |
https://wts.dev/posts/password-leak/ |