The QuickType feature in the Keyboards subsystem in Apple iOS before 8.1 collects typing-prediction data from fields with an off autocomplete attribute, which makes it easier for attackers to discover credentials by reading credential values within unintended DOM input elements.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
https://support.apple.com/kb/HT6541 | vendor advisory |
http://www.securitytracker.com/id/1031077 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/97666 | vdb entry |
http://www.securityfocus.com/archive/1/533747 | vendor advisory |
http://www.securityfocus.com/bid/70660 | vdb entry |