First published: Thu Mar 24 2016(Updated: )
Messages in Apple iOS before 9.3 does not ensure that an auto-fill action applies to the intended message thread, which allows remote authenticated users to obtain sensitive information by providing a crafted sms: URL and reading a thread.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPhone OS | <=9.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1763 is categorized as a medium severity vulnerability.
The best way to fix CVE-2016-1763 is to upgrade your iOS device to version 9.3 or later.
CVE-2016-1763 affects Apple iOS versions prior to 9.3.
CVE-2016-1763 can be exploited by sending a crafted sms: URL that allows unauthorized access to message threads.
CVE-2016-1763 can be exploited by remote authenticated users.