The CoreProcesses component in Apple Mac OS X 10.7 before 10.7.2 does not prevent a system window from receiving keystrokes in the locked-screen state, which might allow physically proximate attackers to bypass intended access restrictions by typing into this window.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published: 2011-10-14T10:00:00

Updated: 2024-08-06T21:51:07.682Z

Reserved: 2010-12-23T00:00:00

Link: CVE-2011-0260

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2011-10-14T10:55:08.230

Modified: 2012-01-14T03:51:31.040

Link: CVE-2011-0260

cve-icon Redhat

No data.