The Keyboards component in Apple iOS before 10 does not properly use a cache for auto-correct suggestions, which allows remote attackers to obtain sensitive information in opportunistic circumstances by leveraging an unintended correction.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://lists.apple.com/archives/security-announce/2016/Sep/msg00008.html | vendor advisory |
http://www.securitytracker.com/id/1036797 | vdb entry |
http://lists.apple.com/archives/security-announce/2016/Sep/msg00002.html | vendor advisory mailing list |
http://www.securityfocus.com/bid/92932 | vdb entry |
https://support.apple.com/HT207143 | vendor advisory |