PatchSiren

PatchSiren cyber security CVE debrief

CVE-2016-7653 Apple CVE debrief

CVE-2016-7653 is a low-severity information-disclosure issue in Apple’s iOS Media Player component. On affected devices, a physically proximate attacker could leverage lockscreen access to obtain sensitive photo and contact information. The CVE was published on 2017-02-20; NVD later marked the record modified on 2026-05-13, which should not be treated as the issue date.

Vendor
Apple
Product
Unknown
CVSS
LOW 2.4
CISA KEV
Not listed in stored evidence
Original CVE published
2017-02-20
Original CVE updated
2026-05-13
Advisory published
2017-02-20
Advisory updated
2026-05-13

Who should care

Anyone responsible for Apple iOS devices before 10.2, especially users or fleets where a phone may be left physically accessible to others. Mobile device administrators should prioritize this for shared, unattended, or kiosk-like usage patterns.

Technical summary

The vulnerability is an information exposure problem (CWE-200) in the Media Player component. NVD describes the impact as confidentiality only, with a CVSS 3.0 vector of AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N. The description states that an attacker with physical proximity can use lockscreen access to view sensitive photos and contacts on affected iOS devices.

Defensive priority

Low severity overall, but worth correcting on any device that may be handled by untrusted people or left unattended in public. Because the weakness is physical-proximity based and affects confidentiality only, it is primarily a privacy risk rather than a system integrity risk.

Recommended defensive actions

  • Update Apple devices to a version newer than iOS 10.2 on systems that are still affected.
  • Follow Apple’s advisory guidance in HT207422 for vendor-recommended remediation.
  • Review lockscreen exposure settings and operational practices for devices that may be physically accessible to others.
  • Prioritize remediation for shared devices, field devices, and any endpoint likely to be left unattended.

Evidence notes

The CVE description states that iOS before 10.2 is affected and that the Media Player component may expose sensitive photo and contact information through lockscreen access. NVD maps the issue to Apple iPhone OS through 10.1.1 and assigns CVSS 3.0 AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N with CWE-200. Apple’s advisory is referenced at https://support.apple.com/HT207422.

Sources and references

Verified primary and authoritative sources

  • CVE-2016-7653 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2016-7653

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2016-7653 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2016-7653

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.