CVE-2009-1680: Infoleak
Safari in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly clear the search history when it is cleared from the Settings application, which allows physically proximate attackers to obtain the search history.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1680?
CVE-2009-1680 is classified as a medium severity vulnerability due to its potential to expose sensitive search history.
How do I fix CVE-2009-1680?
To fix CVE-2009-1680, users should update their iPhone or iPod touch to a more recent version of the iPhone OS that addresses this vulnerability.
Who is affected by CVE-2009-1680?
CVE-2009-1680 affects users of Apple iPhone OS versions 1.0 through 2.2.1 and iPod touch OS versions 1.1 through 2.2.1.
What attack vector is associated with CVE-2009-1680?
CVE-2009-1680 allows physically proximate attackers to gain access to the search history of affected devices.
What are the implications of CVE-2009-1680?
The implications of CVE-2009-1680 include unauthorized access to potentially sensitive information stored in the search history.