CVE-2015-1106: Infoleak
The QuickType feature in the Keyboards subsystem in Apple iOS before 8.3 allows physically proximate attackers to discover passcodes by reading the lock screen during use of a Bluetooth keyboard.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1106?
CVE-2015-1106 has a medium severity rating as it allows attackers to discover passcodes by observing the device during Bluetooth keyboard use.
How do I fix CVE-2015-1106?
To mitigate CVE-2015-1106, update to Apple iOS version 8.3 or later.
Who is affected by CVE-2015-1106?
CVE-2015-1106 affects users of Apple iOS versions prior to 8.3, particularly when using a Bluetooth keyboard.
What type of attacks does CVE-2015-1106 enable?
CVE-2015-1106 enables physical proximity attacks that allow observers to capture passcodes as users type on the device.
What is the impact of CVE-2015-1106 on security?
The impact of CVE-2015-1106 is the potential compromise of device security due to unauthorized access to user passcodes.