CVE-2014-4450 describes a privacy vulnerability in Apple iOS before version 8.1, specifically within the QuickType feature of the Keyboards subsystem. This flaw allowed the system to collect typing-prediction data from input fields even when the autocomplete attribute was set to "off," potentially exposing sensitive credential values to an attacker who could access unintended DOM input elements. The vulnerability has a low CVSS score of 1.9, indicating local access and medium attack complexity are required, with only a partial confidentiality impact. There is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage, suggesting it is not a widely exploited or discussed threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 8.0.2CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:M/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.