CVE-2016-4781 is a passcode bypass vulnerability affecting Apple iOS devices running versions prior to 10.2, specifically within the SpringBoard component. This medium-severity flaw (CVSS 6.8) allows a physically proximate attacker to bypass the passcode attempt counter and unlock a device through unspecified vectors, leading to high confidentiality, integrity, and availability impacts. While no public exploit code (Metasploit, Nuclei, ExploitDB) is available and it's not listed on the KEV catalog, the vulnerability received some community discussion and media coverage at the time of its disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.1.1CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.