CVE-2014-4450
Apple Security Advisory 2014-10-20-1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The QuickType feature in the Keyboards subsystem in Apple iOS before 8.1 collects typing-prediction data from fields with an off autocomplete attribute, which makes it easier for attackers to discover credentials by reading credential values within unintended DOM input elements.
La caracteristica QuickType en el subsistema Keyboards en Apple iOS anterior a 8.1 recoge datos de la previsiĆ³n de escritura de campos con un atributo de autocompletado apagado, lo que facilita a atacantes descubrir credenciales mediante la lectura de los valores de credenciales dentro de elementos no intencionados de entradas DOM.
iOS 8.1 is now available and addresses bluetooth, insufficient cryptographic protection, and various other vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-06-20 CVE Reserved
- 2014-10-21 CVE Published
- 2024-08-06 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-255: Credentials Management Errors
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/70660 | Vdb Entry | |
http://www.securitytracker.com/id/1031077 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/97666 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.securityfocus.com/archive/1/533747 | 2017-08-29 | |
https://support.apple.com/kb/HT6541 | 2017-08-29 |