CVE-2013-5164: Apple iPhone OS

Low severity, CVSS 3.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Multiple race conditions in the Phone app in Apple iOS before 7.0.3 allow physically proximate attackers to bypass the locked state, and dial the telephone numbers in arbitrary Contacts entries, by visiting the Contacts pane.

Affected products

  • Apple iPhone OS: up to and including 7.0.2; version 7.0 only; version 7.0.1 only

Published 2013-10-24. Last modified 2026-06-16.