CAPEC Definitions

    CAPEC Definitions / CAPEC-626

    CAPEC-626: Smudge Attack

    Attacks that reveal the password/passcode pattern on a touchscreen device by detecting oil smudges left behind by the user’s fingers.

    Severity:
    Possibility:

    Extended Description

    No Extended Description.

    Mitigations

    Strong physical security of the device.

    Relationships with other CAPECs

    CAPEC-395: Bypassing Electronic Locks and Access Controls

    Prerequisites

    The attacker must have physical access to the device.

    Related Weaknesses

    No related Weaknesses found.

    CAPEC-626: Smudge Attack | CVE-DB