CVE-2013-4616: Apple iPhone OS

Medium severity, CVSS 5.8. EPSS: 0.9% chance of exploitation in the next 30 days.

The WifiPasswordController generateDefaultPassword method in Preferences in Apple iOS 6 and earlier relies on the UITextChecker suggestWordInLanguage method for selection of Wi-Fi hotspot WPA2 PSK passphrases, which makes it easier for remote attackers to obtain access via a brute-force attack that leverages the insufficient number of possible passphrases.

Affected products

  • Apple iPhone OS: up to and including 6.0; version 1.0.0 only; version 1.0.1 only; version 1.0.2 only; version 1.1.0 only; version 1.1.1 only; …

Published 2013-06-18. Last modified 2026-06-16.