CVE-2009-2204: Critical severity iphone os vulnerability
Unspecified vulnerability in the CoreTelephony component in Apple iPhone OS before 3.0.1 allows remote attackers to execute arbitrary code, obtain GPS coordinates, or enable the microphone via an SMS message that triggers memory corruption, as demonstrated by Charlie Miller at SyScan '09 Singapore.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2204?
CVE-2009-2204 is considered a critical vulnerability due to its potential to allow remote code execution and access to sensitive functionalities.
How do I fix CVE-2009-2204?
The only effective fix for CVE-2009-2204 is to update to a version of iPhone OS that has addressed the vulnerability, specifically version 3.0.1 or later.
What type of attack does CVE-2009-2204 enable?
CVE-2009-2204 enables attackers to execute arbitrary code, access GPS coordinates, or activate the microphone via a malicious SMS message.
Which versions of iPhone OS are affected by CVE-2009-2204?
CVE-2009-2204 affects iPhone OS versions up to and including 3.0.
Who discovered CVE-2009-2204?
CVE-2009-2204 was demonstrated by security researcher Charlie Miller at the SyScan '09 conference in Singapore.