A session management issue was addressed with improved...
Low severity
Unreviewed
Published
Jan 13, 2024
to the GitHub Advisory Database
•
Updated Jan 28, 2024
Description
Published by the National Vulnerability Database
Jan 12, 2024
Published to the GitHub Advisory Database
Jan 13, 2024
Last updated
Jan 28, 2024
A session management issue was addressed with improved checks. This issue is fixed in Magic Keyboard Firmware Update 2.0.6. An attacker with physical access to the accessory may be able to extract its Bluetooth pairing key and monitor Bluetooth traffic.
References