Apple macOS WindowServer Lock Screen Keyboard Event Capture Vulnerability

Vulnerability

A vulnerability in the WindowServer component of Apple macOS Sonoma, Sequoia, and Ventura allows apps to capture keyboard events from the lock screen. This issue arises from a logic flaw in state management, which could potentially be exploited to intercept keystrokes while the device is locked.

Impact

Exploitation of this vulnerability could lead to unauthorized capture of keyboard inputs from the lock screen, allowing for interception of typed information such as passwords or other sensitive data.

Remediation

Users can update to macOS Sonoma 14.7.2, macOS Sequoia 15.2, or macOS Ventura 13.7.2 to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
0.0
exploitability
4.7
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.