usnistgov / mobile-threat-catalogue

NIST/NCCoE Mobile Threat Catalogue
https://pages.nist.gov/mobile-threat-catalogue
Other
142 stars 40 forks source link

AUT-1: Clarify threat is sensitive data displayed by locked device #166

Closed sdog-nist closed 7 years ago

sdog-nist commented 7 years ago

New Threat

Threat ID AUT-1

Threat Category: Authentication / User to Device

Threat: Exposure of sensitive information contained in displayed push notifications or OS dialogs that display even when the device is locked.

Threat Origin:

Exploit Example:

CVE Example:

Possible Countermeasures:

References: