First published: Thu Oct 24 2013(Updated: )
Multiple race conditions in the Phone app in Apple iOS before 7.0.3 allow physically proximate attackers to bypass the locked state, and dial the telephone numbers in arbitrary Contacts entries, by visiting the Contacts pane.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPhone OS | <=7.0.2 | |
Apple iPhone OS | =7.0 | |
Apple iPhone OS | =7.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-5164 has a medium severity rating due to its potential to allow unauthorized access to contact numbers.
The vulnerability CVE-2013-5164 can be fixed by upgrading to Apple iOS version 7.0.3 or later.
CVE-2013-5164 affects Apple iOS versions prior to 7.0.3, including 7.0, 7.0.1, and 7.0.2.
Physically proximate attackers can exploit CVE-2013-5164 to bypass the lock screen and access contact numbers.
The impact of CVE-2013-5164 allows attackers to dial telephone numbers stored in arbitrary Contacts, breaching user privacy.