First published: Thu Sep 18 2014(Updated: )
The Sandbox Profiles implementation in Apple iOS before 8 does not properly restrict the third-party app sandbox profile, which allows attackers to obtain sensitive Apple ID information via a crafted app.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
iPhone OS | <=7.1.2 | |
iPhone OS | =7.0 | |
iPhone OS | =7.0.1 | |
iPhone OS | =7.0.2 | |
iPhone OS | =7.0.3 | |
iPhone OS | =7.0.4 | |
iPhone OS | =7.0.5 | |
iPhone OS | =7.0.6 | |
iPhone OS | =7.1 | |
iPhone OS | =7.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-4362 has a high severity due to its potential exploitation to access sensitive Apple ID information.
CVE-2014-4362 allows attackers to bypass restrictions in the third-party app sandbox, compromising user data.
To fix CVE-2014-4362, users are advised to update their Apple iOS devices to version 8 or later.
CVE-2014-4362 affects Apple iOS versions prior to 8, including all versions up to 7.1.1.
Using devices running an affected iOS version can be risky as they are vulnerable to exploitation of sensitive information.