First published: Fri Oct 23 2015(Updated: )
Notification Center in Apple iOS before 9.1 mishandles changes to "Show on Lock Screen" settings, which allows physically proximate attackers to obtain sensitive information by looking for a (1) Phone or (2) Messages notification on the lock screen soon after a setting was disabled.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPhone OS | <=9.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7000 is considered a medium severity vulnerability due to its potential for information disclosure.
To mitigate CVE-2015-7000, update your iOS device to version 9.1 or later.
CVE-2015-7000 can expose sensitive information displayed in Phone or Messages notifications on the lock screen.
CVE-2015-7000 affects users of Apple iOS devices running versions prior to 9.1.
CVE-2015-7000 was disclosed in October 2015 as part of a security announcement by Apple.