CVE-2014-4362: Infoleak
Published Sep 18, 2014
·Updated
The Sandbox Profiles implementation in Apple iOS before 8 does not properly restrict the third-party app sandbox profile, which allows attackers to obtain sensitive Apple ID information via a crafted app.
Affected Software
10 affected components
apple iPhone OS<=7.1.2
apple iPhone OS=7.0
apple iPhone OS=7.0.1
apple iPhone OS=7.0.2
apple iPhone OS=7.0.3
apple iPhone OS=7.0.4
apple iPhone OS=7.0.5
apple iPhone OS=7.0.6
apple iPhone OS=7.1
apple iPhone OS=7.1.1
Event History
Sep 18, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-4362?
CVE-2014-4362 has a high severity due to its potential exploitation to access sensitive Apple ID information.
2
How does CVE-2014-4362 affect Apple iOS?
CVE-2014-4362 allows attackers to bypass restrictions in the third-party app sandbox, compromising user data.
3
How do I fix CVE-2014-4362?
To fix CVE-2014-4362, users are advised to update their Apple iOS devices to version 8 or later.
4
What versions of iOS are affected by CVE-2014-4362?
CVE-2014-4362 affects Apple iOS versions prior to 8, including all versions up to 7.1.1.
5
Is it safe to use devices running iOS affected by CVE-2014-4362?
Using devices running an affected iOS version can be risky as they are vulnerable to exploitation of sensitive information.