First published: Fri Dec 11 2015(Updated: )
Siri in Apple iOS before 9.2 allows physically proximate attackers to bypass an intended client-side protection mechanism and obtain sensitive content-notification information by listening to a device in the lock-screen state.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPhone OS | <=9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7080 is considered a moderate severity vulnerability due to the potential for sensitive information disclosure.
To fix CVE-2015-7080, upgrade your Apple iOS to version 9.2 or later.
CVE-2015-7080 affects Apple iOS versions prior to 9.2 on devices with Siri enabled.
CVE-2015-7080 can be exploited by physically proximate attackers who gain access to the device during the lock-screen state.
The impact of CVE-2015-7080 allows attackers to bypass client-side protections and access sensitive content notifications.