SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2009-0961

The Mail component in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 dismisses the call approval dialog when another alert appears, which might allow remote attackers to force the iPhone to place a call without user…

MEDIUM 5.0EPSS 6.38%

Does this matter?

Lower severity and a low EPSS score (6.38%). Track it; it rarely justifies an emergency change on its own.

Description

The Mail component in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 dismisses the call approval dialog when another alert appears, which might allow remote attackers to force the iPhone to place a call without user approval by causing an application to trigger an alert.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS
6.38% probability · 93th percentile
CISA KEV
Not listed
Affected
apple/iphone os · apple/ipod touch
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.