OSVDB ID: 85633

Title: Apple iOS UIKit UIWebView Unencrypted File Disclosure

Info

Disclosure

Sep 19, 2012

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Sep 19, 2012

Description

Apple iOS contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when UIWebView of UIKit fails to properly use the Data Protection feature, which will result in unencrypted files being left on the file system. This may allow a context-dependent attacker to gain access to potentially sensitive information.

Classification

Location: Context Dependent
Attack Type: Information Disclosure
Impact: Loss of Confidentiality
Solution: Upgrade
Exploit: Exploit Private
Disclosure: Vendor Verified, Coordinated Disclosure

Solution

Upgrade to version 6 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

Apple Inc.

Apple iOS

5.1.1

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/85633