PT-2015-2452 · Apple · Ios
William Redwood
·
Published
2015-10-23
·
Updated
2016-12-24
·
CVE-2015-7000
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apple iOS versions prior to 9.1
Description
The issue is related to the Notification Center component in the iOS operating system, which lacks protection for certain data. This can be exploited by a local attacker to access protected information by viewing call and message notifications on the lock screen. Specifically, the problem arises when changes to the "Show on Lock Screen" settings are mishandled, allowing an attacker to obtain sensitive information by looking for notifications on the lock screen soon after a setting was disabled.
Recommendations
For Apple iOS versions prior to 9.1, update to version 9.1 or later to resolve the issue. As a temporary workaround, consider disabling the "Show on Lock Screen" feature for sensitive information, such as phone calls and messages, to minimize the risk of exploitation. Restrict access to the lock screen to prevent physically proximate attackers from viewing notifications.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ios