CVE-2016-4644: Apple Tv
Medium severity, CVSS 6.5. EPSS: 1.3% chance of exploitation in the next 30 days.
In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, a downgrade issue existed with HTTP authentication credentials saved in Keychain. This issue was addressed by storing the authentication types with the credentials.
Affected products
- Apple Apple Tv: before 9.2.2 (fixed in 9.2.2)
- Apple iPhone OS: before 9.3.3 (fixed in 9.3.3)
- Apple Mac OS: from 10.11.0, before 10.11.6 (fixed in 10.11.6)
Published 2019-01-11. Last modified 2026-06-17.