CVE-2016-7638: Medium severity apple iPhone OS vulnerability
Published Feb 20, 2017
·Updated
An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "Find My iPhone" component, which allows physically proximate attackers to disable this component by bypassing authentication.
Affected Software
1 affected component
apple iPhone OS<=10.1.1
Event History
Feb 20, 2017
CVE Published
via MITRE·08:35 AM
Data Sourced
via MITRE·08:35 AM
Description
Data Sourced
via NVD·08:59 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-7638?
CVE-2016-7638 has a high severity rating due to its potential exploitation by physically proximate attackers.
2
How do I fix CVE-2016-7638?
To fix CVE-2016-7638, update your iOS device to version 10.2 or later.
3
What systems are affected by CVE-2016-7638?
CVE-2016-7638 affects iOS versions prior to 10.2.
4
What vulnerability does CVE-2016-7638 address?
CVE-2016-7638 addresses a flaw in the "Find My iPhone" feature that allows attackers to disable it through authentication bypass.
5
Who can exploit CVE-2016-7638?
CVE-2016-7638 can be exploited by any physically proximate attacker with access to the device.