CVE-2017-2399: Apple iPhone OS

Medium severity, CVSS 4.6. EPSS: 0.1% chance of exploitation in the next 30 days.

An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the "Pasteboard" component. It allows physically proximate attackers to read the pasteboard by leveraging the use of an encryption key derived only from the hardware UID (rather than that UID in addition to the user passcode).

Affected products

  • Apple iPhone OS: up to and including 10.2.1

Published 2017-04-02. Last modified 2026-06-17.