CVE-2014-4450
Last modified
CVE-2014-4450 is a vulnerability of currently unknown severity. The QuickType feature in the Keyboards subsystem in Apple iOS before 8.1 collects typing-prediction data from fields with an off autocomplete attribute, which makes it easier for attackers to discover credentials by reading credential values within unintended DOM input elements.. EPSS estimates a 0.31% chance of exploitation in the next 30 days.
Description
The QuickType feature in the Keyboards subsystem in Apple iOS before 8.1 collects typing-prediction data from fields with an off autocomplete attribute, which makes it easier for attackers to discover credentials by reading credential values within unintended DOM input elements.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apple | Iphone Os | <= 8.0.2 |
References
- https://support.apple.com/kb/HT6541Vendor Advisory
- https://support.apple.com/kb/HT6541Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-4450?
How severe is CVE-2014-4450?
How do I fix CVE-2014-4450?
Are you affected by CVE-2014-4450?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
