CVE-2016-4740
published 2016-09-18CVE-2016-4740: Apple iOS before 10, when Handoff for Messages is used, does not ensure that a Messages signin has occurred before displaying messages, which might allow…
PriorityP46low2.9CVSS 3.0
AVLACHPRNUINSUCLINAN
EPSS
0.31%
23.6th percentile
Apple iOS before 10, when Handoff for Messages is used, does not ensure that a Messages signin has occurred before displaying messages, which might allow attackers to obtain sensitive information via unspecified vectors.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | iphone_os | <= 9.3.5 | — |
CVSS provenance
nvdv3.02.9LOWCVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2016-4740: iOS 10
vendor_apple·2016-09-13·CVSS 2.9
CVE-2016-4740 [LOW] CVE-2016-4740: iOS 10
Apple Security Update: About the security content of iOS 10
Product: iOS
Version: 10
CVE: CVE-2016-4740
Component: Messages
Impact: Messages may be visible on a device that has not signed in to Messages
Description: An issue existed when using Handoff for Messages. This issue was resolved via better state management.
GHSA
GHSA-8f4r-xmjq-6mwh: Apple iOS before 10, when Handoff for Messages is used, does not ensure that a Messages signin has occurred before displaying messages, which might al
ghsa_unreviewed·2022-05-17
CVE-2016-4740 [LOW] CWE-200 GHSA-8f4r-xmjq-6mwh: Apple iOS before 10, when Handoff for Messages is used, does not ensure that a Messages signin has occurred before displaying messages, which might al
Apple iOS before 10, when Handoff for Messages is used, does not ensure that a Messages signin has occurred before displaying messages, which might allow attackers to obtain sensitive information via unspecified vectors.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.apple.com/archives/security-announce/2016/Sep/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2016/Sep/msg00008.htmlhttp://www.securityfocus.com/bid/92932http://www.securitytracker.com/id/1036797https://support.apple.com/HT207143http://lists.apple.com/archives/security-announce/2016/Sep/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2016/Sep/msg00008.htmlhttp://www.securityfocus.com/bid/92932http://www.securitytracker.com/id/1036797https://support.apple.com/HT207143
2016-09-18
Published