CVE-2014-4453 describes a privacy vulnerability in Apple iOS before 8.1.1 and OS X before 10.10.1, where Spotlight or Safari could transmit location data during Spotlight Suggestions server connections. This could allow remote attackers to potentially obtain sensitive user information. With a CVSS score of 5.0 (AV:N/AC:L/Au:N/C:P/I:N/A:N), it indicates a network-based attack with low complexity, requiring no authentication, resulting in partial confidentiality impact without affecting integrity or availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in CISA's KEV catalog. Community discussion and media coverage are minimal, with only one article mentioning it in the context of broader iOS updates.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 8.1CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:8.0:*:*:*:*:*:*:* | ||
8.0.1CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:8.0.1:*:*:*:*:*:*:* | ||
8.0.2CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:8.0.2:*:*:*:*:*:*:* | ||
<= 10.10.0CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.