Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Jack Lawrence

#39995of 53,633
6.8Total CVSS
Vulnerabilities · 1
PT-2015-2270
6.8
2015-10-09
Apple · Os X · CVE-2015-5849
**Name of the Vulnerable Software and Affected Versions** Apple OS X versions prior to 10.11 **Description** The issue is related to the filtering implementation in AppleEvents, which mishandles attempts to send events to a different user. This can be exploited by attackers to bypass intended access restrictions, potentially allowing them to access protected information. The exploitation can be done by leveraging a screen-sharing connection. **Recommendations** For Apple OS X versions prior to 10.11, consider disabling the screen-sharing feature as a temporary workaround to minimize the risk of exploitation. Restrict access to sensitive information and functions until a fix is available.