CVE-2014-4450

LOW

Description

The QuickType feature in the Keyboards subsystem in Apple iOS before 8.1 collects typing-prediction data from fields with an off autocomplete attribute, which makes it easier for attackers to discover credentials by reading credential values within unintended DOM input elements.

References

http://www.securityfocus.com/archive/1/533747

http://www.securityfocus.com/bid/70660

http://www.securitytracker.com/id/1031077

https://exchange.xforce.ibmcloud.com/vulnerabilities/97666

https://support.apple.com/kb/HT6541

Details

Source: MITRE

Published: 2014-10-22

Updated: 2017-08-29

Type: CWE-255

Risk Information

CVSS v2.0

Base Score: 1.9

Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N

Impact Score: 2.9

Exploitability Score: 3.4

Severity: LOW