CVE-2016-4620
published 2016-09-18CVE-2016-4620: The Sandbox Profiles component in Apple iOS before 10 does not properly restrict access to directory metadata for SMS draft directories, which allows attackers…
PriorityP411low3.3CVSS 3.0
AVLACLPRNUIRSUCLINAN
EPSS
0.83%
54.1th percentile
The Sandbox Profiles component in Apple iOS before 10 does not properly restrict access to directory metadata for SMS draft directories, which allows attackers to discover text-message recipients via a crafted app.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | iphone_os | <= 9.3.5 | — |
CVSS provenance
nvdv3.03.3LOWCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2016-4620: iOS 10
vendor_apple·2016-09-13·CVSS 3.3
CVE-2016-4620 [LOW] CVE-2016-4620: iOS 10
Apple Security Update: About the security content of iOS 10
Product: iOS
Version: 10
CVE: CVE-2016-4620
Component: Sandbox Profiles
Impact: A malicious application may be able to determine whom a user is texting
Description: An access control issue existed in SMS draft directories. This issue was addressed by preventing apps from stat'ing the affected directories.
GHSA
GHSA-6jg9-q26r-4x67: The Sandbox Profiles component in Apple iOS before 10 does not properly restrict access to directory metadata for SMS draft directories, which allows
ghsa_unreviewed·2022-05-17
CVE-2016-4620 [MEDIUM] CWE-200 GHSA-6jg9-q26r-4x67: The Sandbox Profiles component in Apple iOS before 10 does not properly restrict access to directory metadata for SMS draft directories, which allows
The Sandbox Profiles component in Apple iOS before 10 does not properly restrict access to directory metadata for SMS draft directories, which allows attackers to discover text-message recipients via a crafted app.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.apple.com/archives/security-announce/2016/Sep/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2016/Sep/msg00008.htmlhttp://www.securityfocus.com/bid/92932http://www.securitytracker.com/id/1036797https://support.apple.com/HT207143http://lists.apple.com/archives/security-announce/2016/Sep/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2016/Sep/msg00008.htmlhttp://www.securityfocus.com/bid/92932http://www.securitytracker.com/id/1036797https://support.apple.com/HT207143
2016-09-18
Published