EIP-2026-101329

PRE-CVE

iphone/ipad phone drive 1.1.1 - Directory Traversal

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-101329. PoCs published by Khashayar Fereidani.

AI-analyzed exploit summary This Python script exploits a directory traversal vulnerability in iPhone/iPad Phone Drive 1.1.1 by sending crafted HTTP requests to access sensitive files on the device. It allows an attacker to retrieve files such as the address book, Safari data, and system files like /etc/passwd.

Description

iphone/ipad phone drive 1.1.1 - Directory Traversal

Exploits (1)

exploitdb WORKING POC
by Khashayar Fereidani · pythonremotehardware
https://www.exploit-db.com/exploits/17645

This Python script exploits a directory traversal vulnerability in iPhone/iPad Phone Drive 1.1.1 by sending crafted HTTP requests to access sensitive files on the device. It allows an attacker to retrieve files such as the address book, Safari data, and system files like /etc/passwd.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: iPhone/iPad Phone Drive 1.1.1
No auth needed
Prerequisites: Network access to the target device · Phone Drive app running on the target device
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026