CVE-2016-4740 is a low-severity vulnerability affecting Apple iOS before version 10, specifically when Handoff for Messages is enabled. This flaw could allow an attacker to obtain sensitive information by displaying messages before a proper sign-in has occurred, though the exact attack vectors are unspecified. The vulnerability has a CVSS score of 2.9, indicating a low impact with local access and high attack complexity. There is no evidence of active exploitation, no public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage beyond a single article mentioning its patch in iOS 10.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 9.3.5CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.