PatchSiren cyber security CVE debrief
CVE-2016-4686 Apple CVE debrief
CVE-2016-4686 is an Apple iOS Contacts component issue where an app could retain Address Book access after the user revoked that access. The CVE description says iOS before 10.1 is affected, and Apple’s advisory is referenced in NVD’s record. This is not a remote code execution issue; the supplied CVSS vector indicates local access, low privileges, and no user interaction. For organizations that manage iOS devices or apps that use Contacts permissions, the practical risk is privacy exposure on unpatched devices.
- Vendor
- Apple
- Product
- Unknown
- CVSS
- MEDIUM 4.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-20
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-20
- Advisory updated
- 2026-05-13
Who should care
iOS fleet administrators, MDM and endpoint management teams, and app owners or developers whose software uses Contacts/Address Book permissions on Apple devices.
Technical summary
The issue affects the Contacts component on iOS and involves access revocation not being enforced for an app’s Address Book access. NVD’s record lists affected iPhone OS versions through 10.0.3, while the CVE description states iOS before 10.1. The supplied CVSS vector (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N) indicates a local, low-privilege issue with limited confidentiality and integrity impact and no availability impact.
Defensive priority
Medium — prioritize remediation on any devices that may still run pre-10.1 iOS, especially where app permission revocation is relied on for privacy control.
Recommended defensive actions
- Update affected Apple devices to iOS 10.1 or later.
- Inventory device versions to identify any systems still on pre-10.1 builds.
- Review apps that request Contacts/Address Book access and verify revocation behavior on managed devices.
- Use MDM or equivalent controls to enforce minimum supported iOS versions.
- Reassess privacy controls and user guidance around Contacts permissions after patching.
Evidence notes
The CVE description supplied here states that iOS before 10.1 is affected and that the Contacts component does not prevent Address Book access after revocation. NVD metadata adds the affected CPE criteria (iPhone OS through 10.0.3), the CVSS v3.0 vector, and a reference to Apple’s advisory at support.apple.com/HT207271. The corpus does not provide exploit details, and no KEV or ransomware signal is supplied.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-4686 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-4686
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-4686 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-4686
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://support.apple.com/HT207271
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.