First published: Thu Mar 29 2018(Updated: )
Files Widget. The File Widget was displaying cached data when in the locked state. This issue was addressed with improved state management.
Credit: Brandon Moore product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS, iPadOS, and watchOS | <11.3 | 11.3 |
iStyle @cosme iPhone OS | <11.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID for this issue is CVE-2018-4168.
The affected software is iOS version up to and excluding 11.3 and Apple iPhone OS version up to and excluding 11.3.
The severity of CVE-2018-4168 is medium, with a severity value of 4.6.
An attacker can exploit this vulnerability by physically accessing a locked device and obtaining sensitive information through the display of cached data in the Files Widget.
Yes, updating the iOS or Apple iPhone OS to version 11.3 or above will fix this vulnerability.