CVE-2016-4620: Apple iPhone OS
Low severity, CVSS 3.3. EPSS: 0.8% chance of exploitation in the next 30 days.
The Sandbox Profiles component in Apple iOS before 10 does not properly restrict access to directory metadata for SMS draft directories, which allows attackers to discover text-message recipients via a crafted app.
Affected products
- Apple iPhone OS: up to and including 9.3.5
Published 2016-09-18. Last modified 2026-06-17.