CVE-2012-3738

iPhone OS < 5.1.1 - Unauthenticated Bypass of Passcode Lock via Emergency Dialer

Title source: llm
STIX 2.1

Description

The Emergency Dialer screen in the Passcode Lock implementation in Apple iOS before 6 does not properly limit the dialing methods, which allows physically proximate attackers to bypass intended access restrictions and make FaceTime calls through Voice Dialing, or obtain sensitive contact information by attempting to make a FaceTime call and reading the contact suggestions.

References (3)

Core 3
Core References
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT5503
Vendor Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2012/Sep/msg00003.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/85620

Scores

EPSS 0.0032
EPSS Percentile 24.7%

Details

CWE
CWE-264
Status published
Products (40)
apple/iphone_os 1.0.0
apple/iphone_os 1.0.1
apple/iphone_os 1.0.2
apple/iphone_os 1.1.0
apple/iphone_os 1.1.1
apple/iphone_os 1.1.2
apple/iphone_os 1.1.3
apple/iphone_os 1.1.4
apple/iphone_os 1.1.5
apple/iphone_os 2.0
... and 30 more
Published Sep 20, 2012
Tracked Since Feb 18, 2026