CVE-2012-0645

iPhone OS < 5.1 - Unauthenticated Email Forwarding via Siri Voice Command

Title source: llm
STIX 2.1

Description

Siri in Apple iOS before 5.1 does not properly restrict the ability of Mail.app to handle voice commands, which allows physically proximate attackers to bypass the locked state via a command that forwards an active e-mail message to an arbitrary recipient.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1026774
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/48288
Mailing List, Vendor Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2012/Mar/msg00001.html

Scores

EPSS 0.0035
EPSS Percentile 27.1%

Details

CWE
CWE-264
Status published
Products (1)
apple/iphone_os < 5.1
Published Mar 08, 2012
Tracked Since Feb 18, 2026