CVE-2012-3718: Apple Mac OS X

Low severity, CVSS 2.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Apple Mac OS X before 10.7.5 and 10.8.x before 10.8.2 allows local users to read passwords entered into Login Window (aka LoginWindow) or Screen Saver Unlock by installing an input method that intercepts keystrokes.

Affected products

  • Apple Mac OS X: up to and including 10.7.4; version 10.0 only; version 10.0.0 only; version 10.0.1 only; version 10.0.2 only; version 10.0.3 only; …
  • Apple Mac OS X Server: up to and including 10.7.4; version 10.0 only; version 10.0.0 only; version 10.0.1 only; version 10.0.2 only; version 10.0.3 only; …

Published 2012-09-20. Last modified 2026-06-16.