Siri in Apple iOS before 7.1.2 allows physically proximate attackers to bypass an intended lock-screen passcode requirement, and read a contact list, via a Siri request that refers to a contact ambiguously.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/68276 | vdb entry |
http://archives.neohapsis.com/archives/bugtraq/2014-06/0174.html | vendor advisory |
http://www.securitytracker.com/id/1030500 | vdb entry |