VulnerabilityModified
CVE-2016-7651
The issue involves the "Accounts" component, which allows local users to bypass intended authorization restrictions by leveraging the mishandling of an app uninstall.
MEDIUM 5.3EPSS 0.27%
Does this matter?
Lower severity and a low EPSS score (0.27%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in certain Apple products. iOS before 10.2 is affected. watchOS before 3.1.1 is affected. The issue involves the "Accounts" component, which allows local users to bypass intended authorization restrictions by leveraging the mishandling of an app uninstall.
- CVSS 3.0
- 5.3 MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- EPSS
- 0.27% probability · 20th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-285
- Affected
- apple/iphone os · apple/watchos
- Source
- product-security@apple.com
References
- http://www.securityfocus.com/bid/94851Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037429
- https://lists.apple.com/archives/security-announce/2016/Dec/msg00001.htmlMailing List, Vendor Advisory
- https://support.apple.com/HT207422Vendor Advisory
- https://support.apple.com/HT207487Vendor Advisory
- http://www.securityfocus.com/bid/94851Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037429
- https://lists.apple.com/archives/security-announce/2016/Dec/msg00001.htmlMailing List, Vendor Advisory
- https://support.apple.com/HT207422Vendor Advisory
- https://support.apple.com/HT207487Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.