The QuickType feature in the Keyboards subsystem in Apple iOS before 8.1 collects typing-prediction data from fields with an off autocomplete attribute, which makes it easier for attackers to discover credentials by reading credential values within unintended DOM input elements.
References
Configurations
History
21 Nov 2024, 02:10
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.securityfocus.com/archive/1/533747 - | |
References | () http://www.securityfocus.com/bid/70660 - | |
References | () http://www.securitytracker.com/id/1031077 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/97666 - | |
References | () https://support.apple.com/kb/HT6541 - Vendor Advisory |
Information
Published : 2014-10-22 10:55
Updated : 2024-11-21 02:10
NVD link : CVE-2014-4450
Mitre link : CVE-2014-4450
CVE.ORG link : CVE-2014-4450
JSON object : View
Products Affected
apple
- iphone_os
CWE
CWE-255
Credentials Management Errors