An adversary with root access may gather credentials by reading securityd’s memory.

Tactics
TA0006

Sub-technique of
T1555


See: MITRE ATT&CK