CAPEC-626: Smudge Attack
Attacks that reveal the password/passcode pattern on a touchscreen device by detecting oil smudges left behind by the user’s fingers.
Overview
CAPEC-626 (Smudge Attack) is a detailed-level attack pattern catalogued by MITRE in the Common Attack Pattern Enumeration and Classification (CAPEC). It describes a recurring method attackers use to exploit software weaknesses.
What the attacker needs
Prerequisites
- The attacker must have physical access to the device.
Skills required
- Medium skill: The attacker must know how to make use of these smudges.
Consequences
What a successful CAPEC-626 attack can achieve.
Bypass Protection Mechanism
Affects: Access Control
How to mitigate it
Defenses that reduce the risk of CAPEC-626.
- Strong physical security of the device.