CVE-2014-1274
published 2014-03-14CVE-2014-1274: FaceTime in Apple iOS before 7.1 allows physically proximate attackers to obtain sensitive FaceTime contact information by using the lock screen for an invalid…
PriorityP46low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.36%
28.9th percentile
FaceTime in Apple iOS before 7.1 allows physically proximate attackers to obtain sensitive FaceTime contact information by using the lock screen for an invalid FaceTime call.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | iphone_os | <= 7.0.6 | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apple iOS 6.1/7.0.5 Facetime facetime-audio:/ Scheme information disclosure (HT6162 / XFDB-91711)
vuldb·2026-05-08·CVSS 2.1
CVE-2014-1274 [LOW] Apple iOS 6.1/7.0.5 Facetime facetime-audio:/ Scheme information disclosure (HT6162 / XFDB-91711)
A vulnerability was found in Apple iOS 6.1/7.0.5. It has been classified as problematic. Affected by this issue is some unknown functionality of the component Facetime. The manipulation as part of facetime-audio:/ Scheme leads to information disclosure.
This vulnerability is listed as CVE-2014-1274. The attack must be carried out locally. There is no available exploit.
Upgrading the affected component is recommended.
GHSA
GHSA-gj7q-p94f-4mqm: FaceTime in Apple iOS before 7
ghsa_unreviewed·2022-05-17
CVE-2014-1274 [LOW] CWE-200 GHSA-gj7q-p94f-4mqm: FaceTime in Apple iOS before 7
FaceTime in Apple iOS before 7.1 allows physically proximate attackers to obtain sensitive FaceTime contact information by using the lock screen for an invalid FaceTime call.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2014-03-14
Published