PT-2016-2103 · Apple · Ios
Videosdebarraquito
·
Publicado
2016-05-20
·
Atualizado
2016-12-02
·
CVE-2016-1852
CVSS v3.1
2.4
Baixa
| Vetor | AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apple iOS versions prior to 9.3.2
Description
The issue is related to Siri in Apple iOS, where data detectors within results are not blocked in the lock-screen state. This allows physically proximate attackers to obtain sensitive contact and photo information. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited. The technical details of exploitation include the lack of blocking of data detectors in the lock-screen state, which can be used by attackers to gain access to sensitive information.
Recommendations
For Apple iOS versions prior to 9.3.2, update to version 9.3.2 or later to resolve the issue. As a temporary workaround, consider disabling Siri when the device is in the lock-screen state to minimize the risk of exploitation. Restrict access to sensitive contact and photo information to minimize the risk of unauthorized access.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ios