CVE-2013-5164: Race Condition
Multiple race conditions in the Phone app in Apple iOS before 7.0.3 allow physically proximate attackers to bypass the locked state, and dial the telephone numbers in arbitrary Contacts entries, by visiting the Contacts pane.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-5164?
CVE-2013-5164 has a medium severity rating due to its potential to allow unauthorized access to contact numbers.
How do I fix CVE-2013-5164?
The vulnerability CVE-2013-5164 can be fixed by upgrading to Apple iOS version 7.0.3 or later.
What versions of iOS are affected by CVE-2013-5164?
CVE-2013-5164 affects Apple iOS versions prior to 7.0.3, including 7.0, 7.0.1, and 7.0.2.
Who can exploit CVE-2013-5164?
Physically proximate attackers can exploit CVE-2013-5164 to bypass the lock screen and access contact numbers.
What is the impact of CVE-2013-5164?
The impact of CVE-2013-5164 allows attackers to dial telephone numbers stored in arbitrary Contacts, breaching user privacy.