CVE-2016-1763

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
24/03/2016
Last modified:
12/04/2025

Description

Messages in Apple iOS before 9.3 does not ensure that an auto-fill action applies to the intended message thread, which allows remote authenticated users to obtain sensitive information by providing a crafted sms: URL and reading a thread.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* 9.2.1 (including)