Downgrade Vulnerability in iOS, tvOS, and OS X from Apple
CVE-2016-4644
6.5MEDIUM
What is CVE-2016-4644?
An issue was identified in various Apple products where HTTP authentication credentials stored in the Keychain could be vulnerable to downgrade attacks. This could potentially allow unauthorized access to sensitive data, as older authentication methods might be leveraged by an attacker. The vulnerabilities observed have now been addressed by ensuring authentication types are securely stored alongside the credentials, enhancing the overall security of the Keychain feature.