CVE-2016-1763: Apple iPhone OS
Low severity, CVSS 3.5. EPSS: 1.2% chance of exploitation in the next 30 days.
Messages in Apple iOS before 9.3 does not ensure that an auto-fill action applies to the intended message thread, which allows remote authenticated users to obtain sensitive information by providing a crafted sms: URL and reading a thread.
Affected products
- Apple iPhone OS: up to and including 9.2.1
Published 2016-03-24. Last modified 2026-06-17.