CVE-2014-4423: Medium severity apple iPhone OS vulnerability
Published Sep 18, 2014
·Updated
The Accounts subsystem in Apple iOS before 8 allows attackers to bypass a sandbox protection mechanism and obtain an active iCloud account's Apple ID and metadata via a crafted application.
Affected Software
10 affected components
apple iPhone OS<=7.1.2
apple iPhone OS=7.0
apple iPhone OS=7.0.1
apple iPhone OS=7.0.2
apple iPhone OS=7.0.3
apple iPhone OS=7.0.4
apple iPhone OS=7.0.5
apple iPhone OS=7.0.6
apple iPhone OS=7.1
apple iPhone OS=7.1.1
Event History
Sep 18, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-4423?
CVE-2014-4423 has a medium severity rating due to the potential for attackers to access sensitive iCloud account information.
2
How do I fix CVE-2014-4423?
To fix CVE-2014-4423, you should update your Apple iPhone OS to version 8.0 or later.
3
Which versions of Apple iOS are affected by CVE-2014-4423?
CVE-2014-4423 affects Apple iOS versions prior to 8.0, including all versions from 7.0 to 7.1.2.
4
What type of attack does CVE-2014-4423 allow?
CVE-2014-4423 allows attackers to bypass sandbox restrictions and obtain access to an active iCloud account's Apple ID and metadata.
5
Is my device at risk if it runs iOS 7.x due to CVE-2014-4423?
Yes, if your device runs any version of iOS 7.x, it is at risk due to the vulnerability outlined in CVE-2014-4423.