CVE-2016-1766: Apple iPhone OS
High severity, CVSS 7.5. EPSS: 1% chance of exploitation in the next 30 days.
The Profiles component in Apple iOS before 9.3 does not properly validate certificates, which allows attackers to spoof an MDM profile trust relationship via unspecified vectors.
Affected products
- Apple iPhone OS: up to and including 9.2.1
Published 2016-03-24. Last modified 2026-06-17.