CVE-2012-3738: Apple iPhone OS
Low severity, CVSS 3.6. EPSS: 0.3% chance of exploitation in the next 30 days.
The Emergency Dialer screen in the Passcode Lock implementation in Apple iOS before 6 does not properly limit the dialing methods, which allows physically proximate attackers to bypass intended access restrictions and make FaceTime calls through Voice Dialing, or obtain sensitive contact information by attempting to make a FaceTime call and reading the contact suggestions.
Affected products
- Apple iPhone OS: up to and including 5.1.1; version 1.0.0 only; version 1.0.1 only; version 1.0.2 only; version 1.1.0 only; version 1.1.1 only; …
Published 2012-09-20. Last modified 2026-06-16.