Executive brief
A security flaw in macOS Monterey could allow an individual with physical access to a Mac to bypass the login screen. This could lead to unauthorized access to the computer's files and applications without knowing the user's password. Apple has released a software update to correct this behavior and ensure the login window remains secure.
Technical details
A consistency issue in the macOS Login Window component allowed for a potential authentication bypass. The vulnerability was rooted in improper state handling during the login process, which could be exploited by an attacker with physical access to the device to gain entry without valid credentials. Apple addressed this by improving state management within the authentication flow. The fix is available in macOS Monterey 12.4.
Affected products
- Apple macOS Monterey Before 12.4
Timeline
- 2026-06-10: advisory: NVD publication date
- 2022-05-16: patched: Release date of macOS Monterey 12.4