CVE-2012-3698

Apple Xcode < 4.4 - Unauthenticated Keychain Entry Exposure via Signed Program

Title source: llm
STIX 2.1

Description

Apple Xcode before 4.4 does not properly compose a designated requirement (DR) during signing of programs that lack bundle identifiers, which allows remote attackers to read keychain entries via a crafted app, as demonstrated by the keychain entries of a (1) helper tool or (2) command-line tool.

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2012/Jul/msg00001.html

Scores

EPSS 0.0110
EPSS Percentile 62.4%

Details

CWE
CWE-264
Status published
Products (27)
apple/xcode 1.5.0
apple/xcode 2.0.0
apple/xcode 2.1.0
apple/xcode 2.2.0
apple/xcode 2.3.0
apple/xcode 2.4.0
apple/xcode 2.4.1
apple/xcode 3.1
apple/xcode 3.1.1
apple/xcode 3.1.2
... and 17 more
Published Jul 26, 2012
Tracked Since Feb 18, 2026