CVE-2016-7634: Infoleak
Published Feb 20, 2017
·Updated
An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "Accessibility" component, which accepts spoken passwords without considering that they are locally audible.
Affected Software
1 affected component
apple iPhone OS<=10.1.1
Event History
Feb 20, 2017
CVE Published
via MITRE·08:35 AM
Data Sourced
via MITRE·08:35 AM
Description
Data Sourced
via NVD·08:59 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-7634?
CVE-2016-7634 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2016-7634?
To fix CVE-2016-7634, update your iOS device to version 10.2 or later.
3
What systems are affected by CVE-2016-7634?
CVE-2016-7634 affects iOS versions before 10.2.
4
What is the main issue with CVE-2016-7634?
The main issue with CVE-2016-7634 is that the Accessibility component allows spoken passwords to be heard by unaudible nearby users.
5
Are there any mitigations for CVE-2016-7634?
The only effective mitigation for CVE-2016-7634 is to upgrade to the latest iOS version.