Unrated severityNVD Advisory· Published May 11, 2012· Updated Apr 29, 2026
CVE-2012-0656
CVE-2012-0656
Description
Race condition in LoginUIFramework in Apple Mac OS X 10.7.x before 10.7.4, when the Guest account is enabled, allows physically proximate attackers to login to arbitrary accounts by entering the account name and no password.
Affected products
4cpe:2.3:o:apple:mac_os_x:10.7.0:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:o:apple:mac_os_x:10.7.0:*:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x:10.7.1:*:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x:10.7.2:*:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x:10.7.3:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- lists.apple.com/archives/security-announce/2012/May/msg00001.htmlnvdVendor Advisory
- support.apple.com/kb/HT5281nvdVendor Advisory
- www.securityfocus.com/bid/53445nvd
- www.securityfocus.com/bid/53459nvd
News mentions
0No linked articles in our index yet.