CVE-2013-7127: Apple Mac OS X

Low severity, CVSS 2.1. EPSS: 0.4% chance of exploitation in the next 30 days.

Apple Safari 6.0.5 on Mac OS X 10.7.5 and 10.8.5 stores cleartext credentials in LastSession.plist, which allows local users to obtain sensitive information by reading this file.

Affected products

  • Apple Mac OS X: version 10.7.5 only; version 10.8.5 only
  • Apple Safari: version 6.0.5 only

Published 2013-12-17. Last modified 2026-06-17.