First published: Sat Oct 18 2014(Updated: )
Bluetooth in Apple OS X before 10.10 does not require encryption for HID Low Energy devices, which allows remote attackers to spoof a device by leveraging previous pairing.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS and macOS | <=10.9.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-4428 is classified as a moderate severity vulnerability due to its potential for device spoofing without encryption.
To remediate CVE-2014-4428, upgrade to OS X 10.10 or later, which enforces encryption for HID Low Energy devices.
CVE-2014-4428 affects Bluetooth Low Energy Human Interface Devices (HID) on Apple OS X versions prior to 10.10.
Yes, CVE-2014-4428 can be exploited remotely by attackers leveraging past pairings to spoof devices.
CVE-2014-4428 affects macOS versions prior to 10.10, specifically those up to 10.9.5.