CVE-2014-4448

iPhone OS < 8.0.2 - Sensitive Information Exposure via House Arrest Encryption Key

Title source: llm
STIX 2.1

Description

House Arrest in Apple iOS before 8.1 relies on the hardware UID for its encryption key, which makes it easier for physically proximate attackers to obtain sensitive information from a Documents directory by obtaining this UID.

References (5)

Core 5
Core References
Vendor Advisory x_refsource_confirm
https://support.apple.com/kb/HT6541
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1031077
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/70661
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/97664
Third Party Advisory, VDB Entry vendor-advisory x_refsource_apple
http://www.securityfocus.com/archive/1/533747

Scores

EPSS 0.0019
EPSS Percentile 9.3%

Details

CWE
CWE-310
Status published
Products (1)
apple/iphone_os < 8.0.2
Published Oct 22, 2014
Tracked Since Feb 18, 2026