Medium severity5.5NVD Advisory· Published Sep 25, 2016· Updated May 6, 2026
CVE-2016-4752
CVE-2016-4752
Description
The SecKeyDeriveFromPassword function in Apple OS X before 10.12 does not use the CF_RETURNS_RETAINED keyword, which allows attackers to obtain sensitive information from process memory by triggering key derivation.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- support.apple.com/HT207170nvdVendor Advisory
- lists.apple.com/archives/security-announce/2016/Sep/msg00006.htmlnvdMailing List
- www.securityfocus.com/bid/93055nvd
- www.securitytracker.com/id/1036858nvd
News mentions
0No linked articles in our index yet.