CVE-2013-5149Apple Iphone OS vulnerability

CWE-2642 documents2 sources
Severity
4.3MEDIUMNVD
EPSS
0.3%
top 46.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 19
Latest updateMay 17

Description

The Push Notifications subsystem in Apple iOS before 7 provides the push-notification token to an app without user approval, which allows attackers to obtain sensitive information via an app that employs a crafted push-notification registration process.

CVSS vector

AV:N/AC:M/C:P/I:N/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

NVDapple/iphone_os6.1.4+47

🔴Vulnerability Details

1
GHSA
GHSA-6959-xfmr-wmpm: The Push Notifications subsystem in Apple iOS before 7 provides the push-notification token to an app without user approval, which allows attackers to2022-05-17
CVE-2013-5149 — Apple Iphone OS vulnerability | cvebase