CVE-2014-8495: Citrix XenMobile

Medium severity, CVSS 5.0. EPSS: 1.6% chance of exploitation in the next 30 days.

Citrix XenMobile MDX Toolkit before 9.0.4, when used to wrap iOS 8 applications, does not properly encrypt cached application data, which allows context-dependent attackers to obtain sensitive information by reading the cache.

Affected products

  • Citrix XenMobile: up to and including 9.0.3; version 8.5 only; version 8.6 only; version 8.7 only; version 9.0 only; version 9.0.2 only

Published 2014-10-31. Last modified 2026-06-17.