CVE-2014-1380: Apple Mac OS X

Low severity, CVSS 2.6. EPSS: 0.4% chance of exploitation in the next 30 days.

The Security - Keychain component in Apple OS X before 10.9.4 does not properly implement keystroke observers, which allows physically proximate attackers to bypass the screen-lock protection mechanism, and enter characters into an arbitrary window under the lock window, via keyboard input.

Affected products

  • Apple Mac OS X: version 10.9 only; version 10.9.1 only; version 10.9.2 only; version 10.9.3 only

Published 2014-07-01. Last modified 2026-06-17.