CVE-2016-4719 is a medium-severity vulnerability affecting Apple iOS before version 10 and watchOS before version 3. It allows a crafted application to access sensitive PlaceData information within the GeoServices component, potentially revealing a user's physical location. The attack requires user interaction (UI:R) and local access (AV:L), but has high confidentiality impact (C:H). There is no evidence of active exploitation, nor are there public exploit modules or proof-of-concept code available. Community discussion and media coverage are minimal, suggesting limited public awareness or exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.2CPE matchmatch criteria | cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* | ||
<= 9.3.5CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.