PT-2005-2469 · Apple · Macos X
Published
2005-06-09
·
Updated
2008-09-05
·
CVE-2005-1473
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Apple Mac OS X version 10.4.1
Description:
The issue allows attackers with physical access to bypass the locked screensaver and launch background applications. This can be achieved by opening a URL from a text input field, exploiting the SecurityAgent component.
Recommendations:
For Apple Mac OS X version 10.4.1, consider restricting physical access to devices to minimize the risk of exploitation. As a temporary workaround, avoid using the text input field to open URLs when the screensaver is locked.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Macos X