Security restrictions bypass in Apple iOS - CVE-2018-4252

 

Security restrictions bypass in Apple iOS - CVE-2018-4252

Published: June 4, 2018


Vulnerability identifier: #VU13131
CSH Severity: Low
CVSS v4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-4252
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a physically local attacker to obtain potentially sensitive information on the target system.

The vulnerability exists due to a permissions error in the Siri component. A physically local attacker can bypass security restrictions and read notifications of content that is set to be not displayed at the lock screen.


Affected software

Apple iOS

How to mitigate CVE-2018-4252

Update to version 11.4.


External References

Related Security Bulletins