CVE-2016-4719: Apple iPhone OS

Medium severity, CVSS 5.5. EPSS: 1% chance of exploitation in the next 30 days.

The GeoServices component in Apple iOS before 10 and watchOS before 3 does not properly restrict access to PlaceData information, which allows attackers to discover physical locations via a crafted application.

Affected products

  • Apple iPhone OS: up to and including 9.3.5
  • Apple watchOS: up to and including 2.2

Published 2016-09-18. Last modified 2026-06-17.