CVE-2016-4595
published 2016-07-22CVE-2016-4595: Safari Login AutoFill in Apple OS X before 10.11.6 allows physically proximate attackers to discover passwords by reading the screen during the login procedure.
PriorityP417medium4.6CVSS 3.0
AVPACLPRNUINSUCHINAN
EPSS
0.35%
27.5th percentile
Safari Login AutoFill in Apple OS X before 10.11.6 allows physically proximate attackers to discover passwords by reading the screen during the login procedure.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | <= 10.11.5 | — |
| apple | os_x_el_capitan_v10.11.6_and_security_update_2016-004 | — | — |
CVSS provenance
nvdv3.04.6MEDIUMCVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2016-4595: OS X El Capitan v10.11.6 and Security Update 2016-004
vendor_apple·2016-07-18·CVSS 4.6
CVE-2016-4595 [MEDIUM] CVE-2016-4595: OS X El Capitan v10.11.6 and Security Update 2016-004
Apple Security Update: About the security content of OS X El Capitan v10.11.6 and Security Update 2016-004
Product: OS X El Capitan v10.11.6 and Security Update 2016-004
CVE: CVE-2016-4595
Component: Safari Login AutoFill
Impact: A user's password may be visible on screen
Description: An issue existed in Safari's password auto-fill. This issue was addressed through improved matching of form fields.
GHSA
GHSA-292m-vfg5-7q62: Safari Login AutoFill in Apple OS X before 10
ghsa_unreviewed·2022-05-17
CVE-2016-4595 [MEDIUM] CWE-200 GHSA-292m-vfg5-7q62: Safari Login AutoFill in Apple OS X before 10
Safari Login AutoFill in Apple OS X before 10.11.6 allows physically proximate attackers to discover passwords by reading the screen during the login procedure.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.apple.com/archives/security-announce/2016/Jul/msg00000.htmlhttp://www.securityfocus.com/bid/91824http://www.securitytracker.com/id/1036348https://support.apple.com/HT206903http://lists.apple.com/archives/security-announce/2016/Jul/msg00000.htmlhttp://www.securityfocus.com/bid/91824http://www.securitytracker.com/id/1036348https://support.apple.com/HT206903
2016-07-22
Published