CVE-2014-4425: Apple Mac OS X

Medium severity, CVSS 4.6. EPSS: 0.3% chance of exploitation in the next 30 days.

CFPreferences in Apple OS X before 10.10 does not properly enforce the "require password after sleep or screen saver begins" setting, which makes it easier for physically proximate attackers to obtain access by leveraging an unattended workstation.

Affected products

  • Apple Mac OS X: up to and including 10.9.5

Published 2014-10-18. Last modified 2026-06-17.