CVE-2018-4244 describes a privacy vulnerability in Apple iOS before version 11.4, specifically within the "Siri Contacts" component. A physically proximate attacker could leverage Siri to discover private contact information without authentication. This medium-severity vulnerability (CVSS 4.6) requires physical access to the device (AV:P) but is low complexity (AC:L) with a high impact on confidentiality (C:H). There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 11.4CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.