The history-clearing feature in Safari in Apple iOS before 7 does not clear the back/forward history of an open tab, which allows physically proximate attackers to obtain sensitive information by leveraging an unattended workstation.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1029054 | vdb entry |
http://archives.neohapsis.com/archives/bugtraq/2014-10/0101.html | vendor advisory |
http://support.apple.com/kb/HT5934 | vendor advisory |
https://support.apple.com/kb/HT6535 | |
http://lists.apple.com/archives/security-announce/2013/Sep/msg00006.html | vendor advisory |