CVE-2016-7651 describes a local authorization bypass vulnerability in the "Accounts" component of Apple iOS before 10.2 and watchOS before 3.1.1. This flaw allows a local attacker to bypass intended authorization restrictions due to mishandling of app uninstallation, potentially leading to limited impact on confidentiality, integrity, and availability. The vulnerability has a CVSSv3 score of 5.3 (Medium) with a low attack complexity and no user interaction required. There is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or KEV entry, though it garnered some community discussion and media coverage at the time of disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.1.1CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
<= 2.2.2CPE matchmatch criteria | cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.