CVE-2012-3733: Infoleak
Messages in Apple iOS before 6, when multiple iMessage e-mail addresses are configured, does not ensure that a reply's sender address matches the recipient address of the original message, which allows remote attackers to obtain potentially sensitive information about alternate e-mail addresses in opportunistic circumstances by reading a reply.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3733?
CVE-2012-3733 is classified as having a medium severity due to potential information disclosure.
How do I fix CVE-2012-3733?
To mitigate CVE-2012-3733, users should upgrade their Apple iOS devices to version 6.0 or later.
What platforms are affected by CVE-2012-3733?
CVE-2012-3733 affects Apple iOS versions prior to 6.0.
Can CVE-2012-3733 lead to data leaks?
Yes, CVE-2012-3733 can potentially expose alternate email addresses through iMessage.
What does CVE-2012-3733 specifically exploit?
CVE-2012-3733 exploits a flaw in iMessage that does not validate the sender's address against the recipient's address.