CVE-2016-4689 describes a vulnerability in Apple iOS versions prior to 10.2, specifically within the Mail application. This flaw allowed the Mail app to fail to alert users when an S/MIME email signature was based on a revoked certificate, potentially leading to a false sense of security regarding email authenticity. With a CVSS score of 7.5 (HIGH), this vulnerability has a low attack complexity and could lead to high integrity impacts, as it could enable attackers to spoof email identities without detection. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion, though it did receive limited media coverage at the time of disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.1.1CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.