CVE-2012-4672: Apple Ichat Server

Medium severity, CVSS 5.8. EPSS: 0.8% chance of exploitation in the next 30 days.

Apple iChat Server does not verify that a request was made for an XMPP Server Dialback response, which allows remote XMPP servers to spoof domains via responses for domains that were not asserted.

Affected products

  • Apple Ichat Server: any version

Published 2012-08-25. Last modified 2026-06-16.