First published: Fri Sep 18 2015(Updated: )
The iTunes Store component in Apple iOS before 9 does not properly delete AppleID credentials from the keychain upon a signout action, which might allow physically proximate attackers to obtain sensitive information via unspecified vectors.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPhone OS | <=8.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-5832 is considered a high severity vulnerability due to its potential to expose sensitive AppleID credentials.
To mitigate CVE-2015-5832, update to Apple iOS version 9 or later if you are currently on a version before 9.
CVE-2015-5832 affects Apple iOS versions before 9, specifically the iTunes Store component.
CVE-2015-5832 could allow attackers to access AppleID credentials stored in the keychain.
Individuals using affected versions of iOS before 9 are at risk if their devices are compromised by physical proximity.