First published: Sun Sep 18 2016(Updated: )
Apple iOS before 10, when Handoff for Messages is used, does not ensure that a Messages signin has occurred before displaying messages, which might allow attackers to obtain sensitive information via unspecified vectors.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPhone OS | <=9.3.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4740 is rated as having low severity due to the specific conditions required for exploitation.
To fix CVE-2016-4740, update your device to iOS version 10 or later.
CVE-2016-4740 affects Apple iOS versions before 10, specifically up to version 9.3.5.
CVE-2016-4740 may allow attackers to gain access to sensitive information by not ensuring that a Messages login has occurred.
While updating is the primary fix for CVE-2016-4740, users are advised to limit sharing of sensitive information using Messages until the device is updated.