CVE-2012-0641: Apple iPhone OS
Medium severity, CVSS 5.0. EPSS: 2.3% chance of exploitation in the next 30 days.
CFNetwork in Apple iOS before 5.1 does not properly construct request headers during parsing of URLs, which allows remote attackers to obtain sensitive information via a malformed URL, a different vulnerability than CVE-2011-3447.
Affected products
- Apple iPhone OS: before 5.1 (fixed in 5.1)
Published 2012-03-08. Last modified 2026-06-16.