A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to access protected user data.
This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
Link | Tags |
---|---|
https://support.apple.com/en-us/124149 | vendor advisory release notes |
https://support.apple.com/en-us/124150 | vendor advisory release notes |
https://support.apple.com/en-us/124151 | vendor advisory release notes |