First published: Mon Apr 26 2021(Updated: )
Siri. Description: A person with physical access may be able to access contacts.
Credit: Anshraj Srivastava @AnshrajSrivas14 UKEF product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPadOS | <14.5 | |
Apple iPhone OS | <14.5 | |
Apple iOS | <14.5 | 14.5 |
Apple iPadOS | <14.5 | 14.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID for this Siri vulnerability is CVE-2021-1862.
CVE-2021-1862 is a vulnerability in Siri where a person with physical access may be able to access contacts.
The software affected by CVE-2021-1862 is Apple iOS versions up to and excluding 14.5, and Apple iPadOS versions up to and excluding 14.5.
To exploit CVE-2021-1862, a person needs physical access to the device and may be able to access contacts through Siri.
Yes, Apple has released a fix for CVE-2021-1862. Users should update their devices to Apple iOS 14.5 or Apple iPadOS 14.5 to address the vulnerability.