VYPR
Unrated severityNVD Advisory· Published Oct 18, 2014· Updated May 6, 2026

CVE-2014-4430

CVE-2014-4430

Description

CoreStorage in Apple OS X before 10.10 retains a volume's encryption keys upon an eject action in the unlocked state, which makes it easier for physically proximate attackers to obtain cleartext data via a remount.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

CoreStorage in OS X before 10.10 fails to clear encryption keys on eject, allowing physically proximate attackers to remount and access cleartext data.

Vulnerability

CoreStorage in Apple OS X before 10.10 retains a volume's encryption keys when the volume is ejected while in the unlocked state. This affects all versions prior to OS X Yosemite v10.10. The bug resides in the CoreStorage volume management component, which does not properly discard cryptographic material upon ejection.

Exploitation

An attacker with physical access to the system can exploit this by ejecting an unlocked encrypted volume and then remounting it. Because the encryption keys are still retained in memory, the remount operation can bypass the need for the user's password, granting access to the cleartext data without authentication.

Impact

Successful exploitation allows a physically proximate attacker to read the contents of an encrypted CoreStorage volume without knowing the encryption passphrase. This results in a complete compromise of confidentiality for data stored on that volume.

Mitigation

Apple addressed this issue in OS X Yosemite v10.10 [1]. Users should upgrade to OS X 10.10 or later. No workaround is available for earlier versions; the only mitigation is to ensure volumes are fully unmounted (not just ejected) or to power off the system before physical access is possible.

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.