PT-2016-2103 · Apple · Ios

Videosdebarraquito

·

Publicado

2016-05-20

·

Atualizado

2016-12-02

·

CVE-2016-1852

CVSS v3.1

2.4

Baixa

VetorAV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apple iOS versions prior to 9.3.2
Description The issue is related to Siri in Apple iOS, where data detectors within results are not blocked in the lock-screen state. This allows physically proximate attackers to obtain sensitive contact and photo information. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited. The technical details of exploitation include the lack of blocking of data detectors in the lock-screen state, which can be used by attackers to gain access to sensitive information.
Recommendations For Apple iOS versions prior to 9.3.2, update to version 9.3.2 or later to resolve the issue. As a temporary workaround, consider disabling Siri when the device is in the lock-screen state to minimize the risk of exploitation. Restrict access to sensitive contact and photo information to minimize the risk of unauthorized access.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-01455
CVE-2016-1852

Produtos afetados

Ios