Title: Apple iOS UIKit UIWebView Unencrypted File Disclosure
Info
Disclosure
Sep 19, 2012
Discovery
Unknown
Dates
Exploit
Unknown
Solution
Sep 19, 2012
Description
Apple iOS contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when UIWebView of UIKit fails to properly use the Data Protection feature, which will result in unencrypted files being left on the file system. This may allow a context-dependent attacker to gain access to potentially sensitive information.
Classification
Location:
Context Dependent
Attack Type:
Information Disclosure
Impact:
Loss of Confidentiality
Solution:
Upgrade
Exploit:
Exploit Private
Disclosure:
Vendor Verified,
Coordinated Disclosure
Solution
Upgrade to version 6 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.