First published: Fri Apr 10 2015(Updated: )
The QuickType feature in the Keyboards subsystem in Apple iOS before 8.3 allows physically proximate attackers to discover passcodes by reading the lock screen during use of a Bluetooth keyboard.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPhone OS | <=8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1106 has a medium severity rating as it allows attackers to discover passcodes by observing the device during Bluetooth keyboard use.
To mitigate CVE-2015-1106, update to Apple iOS version 8.3 or later.
CVE-2015-1106 affects users of Apple iOS versions prior to 8.3, particularly when using a Bluetooth keyboard.
CVE-2015-1106 enables physical proximity attacks that allow observers to capture passcodes as users type on the device.
The impact of CVE-2015-1106 is the potential compromise of device security due to unauthorized access to user passcodes.