CVE-2016-7638 describes an authentication bypass vulnerability in the "Find My iPhone" component of Apple iOS versions prior to 10.2. A physically proximate attacker could exploit this flaw to disable the feature without proper authentication. Rated with a CVSS score of 4.6 (Medium), the vulnerability has a low attack complexity and requires physical access, but could lead to high availability impact by preventing the device from being located. There is no evidence of active exploitation, public exploit code, or significant community discussion, with only one article covering the patch.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.1.1CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.