Siri in Apple iOS before 9.3.2 does not block data detectors within results in the lock-screen state, which allows physically proximate attackers to obtain sensitive contact and photo information via unspecified vectors.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1035890 | vdb entry third party advisory |
http://lists.apple.com/archives/security-announce/2016/May/msg00002.html | mailing list vendor advisory |
https://support.apple.com/HT206568 | vendor advisory |