Enterprise & Mobile

Information Disclosure

Siri (iPhone 8 and later) - Meeting/Event Disclosure on Locked iPhone

Siri(iPhone 8 and later) – Meeting/Event Disclosure on Locked iPhone A privacy risk in Siri is where an attacker with physical access to a locked iPhone can view all the scheduled events and

2.4
/ 10
Low
CVSS v3.1
ADVISORY ID
PS65
PUBLISHED
2023-04-14
CVE IDs
CVE-2022-32871
VENDORS
Apple
PUBLIC EXPLOIT
None indexed
CWE
PRODUCT
Siri / iOS
CVSS VECTOR
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

Siri(iPhone 8 and later) – Meeting/Event Disclosure on Locked iPhone

A privacy risk in Siri is where an attacker with physical access to a locked iPhone can view all the scheduled events and meetings. An attacker with physical access to a locked iPhone to bypass the need for specific time information when requesting scheduled events or meetings. By simply requesting a meeting or event on a specific date, such as April 24th, and specifying "all day" as the time, Siri will reveal all scheduled meetings or invites for that date.

Vulnerability details

Vulnerability details

CVE-2022-32871
Low | 2.4

Siri(iPhone 8 and later) – Meeting/Event Disclosure on Locked iPhone A privacy risk in Siri is where an attacker with physical access to a locked iPhone can view all the scheduled events and meetings.

Impact:
Limited data disclosure
DISCLOSURE

Disclosure timeline

2022-04-12 Reported On

2023-03-16 Made Public On

2022-09-13 Fixed On

Credits

Amit kumar