CVE-2015-5906: Infoleak
Published Sep 18, 2015
·Updated
The HTML form implementation in WebKit in Apple iOS before 9 does not prevent QuickType access to the final character of a password, which might make it easier for remote attackers to discover a password by leveraging a later prediction containing that character.
Affected Software
1 affected component
apple iPhone OS<=8.4.1
Event History
Sep 18, 2015
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-5906?
CVE-2015-5906 is classified as a medium severity vulnerability.
2
How do I fix CVE-2015-5906?
To mitigate CVE-2015-5906, users should upgrade their iOS to version 9 or later.
3
Who is affected by CVE-2015-5906?
CVE-2015-5906 affects Apple iOS versions before 9, specifically versions up to 8.4.1.
4
What vulnerability does CVE-2015-5906 exploit?
CVE-2015-5906 exploits the HTML form implementation in WebKit, allowing QuickType access to password characters.
5
Can CVE-2015-5906 lead to remote attacks?
Yes, CVE-2015-5906 can facilitate remote attacks by allowing attackers to discover passwords through predictive text.