CVE-2014-4356: Infoleak
Apple iOS before 8 does not follow the intended configuration setting for text-message preview on the lock screen, which allows physically proximate attackers to obtain sensitive information by reading this screen.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4356?
CVE-2014-4356 has a medium severity level as it allows unauthorized users to view sensitive information through the lock screen.
How do I fix CVE-2014-4356?
To address CVE-2014-4356, update your device to iOS version 8 or later to ensure sensitive information is protected.
What versions of iOS are affected by CVE-2014-4356?
CVE-2014-4356 affects all versions of Apple iOS from 7.0 to 7.1.2, prior to the release of iOS 8.
What type of attack does CVE-2014-4356 involve?
CVE-2014-4356 is susceptible to physical proximity attacks where an attacker can read text-message previews on the lock screen.
What specific configuration issue does CVE-2014-4356 reveal?
CVE-2014-4356 shows that Apple iOS fails to adhere to the configured settings for displaying message previews on the lock screen.