CVE-2014-1281: Low severity apple iPhone OS vulnerability
Published Mar 14, 2014
·Updated
Photos Backend in Apple iOS before 7.1 does not properly manage the asset-library cache during deletions, which allows physically proximate attackers to obtain sensitive photo data by launching the Photos app and looking under a transparent image.
Affected Software
7 affected components
apple iPhone OS<=7.0.6
apple iPhone OS=7.0
apple iPhone OS=7.0.1
apple iPhone OS=7.0.2
apple iPhone OS=7.0.3
apple iPhone OS=7.0.4
apple iPhone OS=7.0.5
Event History
Mar 14, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Data Sourced
via NVD·10:55 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-1281?
CVE-2014-1281 has a medium severity rating, indicating a moderate risk to users.
2
How do I fix CVE-2014-1281?
To remediate CVE-2014-1281, users should update their Apple iOS devices to version 7.1 or later.
3
What kind of attacks are possible due to CVE-2014-1281?
CVE-2014-1281 enables physically proximate attackers to access sensitive photo data through the Photos app.
4
Which devices are affected by CVE-2014-1281?
CVE-2014-1281 affects Apple iOS versions prior to 7.1.
5
Can I still use my device if it is affected by CVE-2014-1281?
While you can still use your device, it is recommended to update to avoid the vulnerability associated with CVE-2014-1281.