Libimobiledevice is a modestly represented library and toolchain for interfacing with Apple mobile devices, embedded across a range of third-party applications and utilities that depend on its device-communication and protocol-handling functions. Its vulnerability footprint, concentrated in the core libimobiledevice, libplist, and libusbmuxd components, skews strongly toward critical-severity outcomes and recurs through memory-safety and access-control weakness classes including out-of-bounds reads, double-free conditions, resource-exhaustion flaws, and improper file-access controls that reflect the low-level parsing demands of USB and protocol handling. Defenders working with third-party or legacy tools that interact with iOS devices should monitor this vendor's advisories closely; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libimobiledevice over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-5209CRITICAL The base64decode function in base64.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memory or cause a denial of service (b | Jan 11, 2017 | 9.1 | 30 | NO | NO |
CVE-2015-10082CRITICAL A vulnerability classified as problematic has been found in UIKit0 libplist 1.12. This affects the function plist_from_xml of the file src/xplist.c of the component XML Handler. Th | Feb 21, 2023 | 9.8 | 29 | NO | NO |
CVE-2017-5545CRITICAL The main function in plistutil.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memory or cause a denial of service (buffer | Jan 21, 2017 | 9.1 | 24 | NO | NO |
CVE-2017-7982MEDIUM Integer overflow in the plist_from_bin function in bplist.c in libimobiledevice/libplist before 2017-04-19 allows remote attackers to cause a denial of service (heap-based buffer o | Apr 20, 2017 | 5.5 | 21 | NO | NO |
CVE-2017-5836HIGH The plist_free_data function in plist.c in libplist allows attackers to cause a denial of service (crash) via vectors involving an integer node that is treated as a PLIST_KEY and t | Mar 3, 2017 | 7.5 | 20 | NO | NO |
CVE-2017-5835HIGH libplist allows attackers to cause a denial of service (large memory allocation and crash) via vectors involving an offset size of zero. | Mar 3, 2017 | 7.5 | 20 | NO | NO |
CVE-2016-5104MEDIUM The socket_create function in common/socket.c in libimobiledevice and libusbmuxd allows remote attackers to bypass intended access restrictions and communicate with services on iOS | Jun 13, 2016 | 5.3 | 20 | NO | NO |
CVE-2017-5834MEDIUM The parse_dict_node function in bplist.c in libplist allows attackers to cause a denial of service (out-of-bounds heap read and crash) via a crafted file. | Mar 3, 2017 | 5.5 | 16 | NO | NO |
userpref.c in libimobiledevice 1.1.4, when $HOME and $XDG_CONFIG_HOME are not set, allows local users to overwrite arbitrary files via a symlink attack on (1) HostCertificate.pem, | Jan 19, 2014 | 3.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libimobiledevice.
Media articles that mention a CVE ID that affects a product developed by Libimobiledevice — matched by CVE ID, not by vendor name.