CVE-2014-4450Apple Iphone OS vulnerability

CWE-2552 documents2 sources
Severity
1.9LOWNVD
EPSS
0.1%
top 65.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 22
Latest updateMay 17

Description

The QuickType feature in the Keyboards subsystem in Apple iOS before 8.1 collects typing-prediction data from fields with an off autocomplete attribute, which makes it easier for attackers to discover credentials by reading credential values within unintended DOM input elements.

CVSS vector

AV:L/AC:M/C:P/I:N/A:NExploitability: 3.4 | Impact: 2.9

Affected Packages1 packages

NVDapple/iphone_os8.0.2

🔴Vulnerability Details

1
GHSA
GHSA-fp7w-8wxv-f27c: The QuickType feature in the Keyboards subsystem in Apple iOS before 82022-05-17
CVE-2014-4450 — Apple Iphone OS vulnerability | cvebase