Apple macOS Sonoma
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*
A vulnerability in the WindowServer component of Apple macOS Sonoma, Sequoia, and Ventura allows apps to capture keyboard events from the lock screen. This issue arises from a logic flaw in state management, which could potentially be exploited to intercept keystrokes while the device is locked.
Exploitation of this vulnerability could lead to unauthorized capture of keyboard inputs from the lock screen, allowing for interception of typed information such as passwords or other sensitive data.
Users can update to macOS Sonoma 14.7.2, macOS Sequoia 15.2, or macOS Ventura 13.7.2 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.