Apple iOS Profiles Spoofing Vulnerability (CVE-2016-1766)
Apple iOS Profiles Spoofing Vulnerability (CVE-2016-1766)
Release date:
Updated on:
Affected Systems:
Apple iOS <9.3
Description:
CVE (CAN) ID: CVE-2016-1766
IOS is an operating system developed by Apple for mobile devices. It supports iPhone, iPod touch, iPad, and Apple TV.
In versions earlier than iOS 9.3, the certificate is not correctly verified in Profiles implementation, and a security vulnerability exists. Attackers can use the constructed MDM configuration file to cheat.
<* Source: Taylor Boyko
Link: https://support.apple.com/en-au/HT206166
*>
Suggestion:
Vendor patch:
Apple
-----
Apple has released a Security Bulletin (HT206166) for this purpose and the corresponding patch:
HT206166: About the security content of iOS 9.3
Link: https://support.apple.com/en-au/HT206166
This article permanently updates the link address: