CVE-2016-4746: Apple iPhone OS

Medium severity, CVSS 5.3. EPSS: 1.8% chance of exploitation in the next 30 days.

The Keyboards component in Apple iOS before 10 does not properly use a cache for auto-correct suggestions, which allows remote attackers to obtain sensitive information in opportunistic circumstances by leveraging an unintended correction.

Affected products

  • Apple iPhone OS: up to and including 9.3.5

Published 2016-09-18. Last modified 2026-06-17.