CVE-2008-3876
Summary
| CVE | CVE-2008-3876 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-09-02 14:24:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Apple iPhone 2.0.2, in some configurations, allows physically proximate attackers to bypass intended access restrictions, and obtain sensitive information or make arbitrary use of the device, via an Emergency Call tap and a Home double-tap, followed by a tap of any contact's blue arrow. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:L/AC:M/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| MacRumors Forums - View Single Post - Major Security Flaw in 2.0.2 | af854a3a-2127-422b-91ae-364da2661108 | forums.macrumors.com | |
| SecurityTracker.com Archives - Apple iPhone Password Locking Bug Lets Physically Local Users Bypass the Password to Access the Device | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| Major Security Flaw in 2.0.2 | MacRumors Forums | af854a3a-2127-422b-91ae-364da2661108 | forums.macrumors.com | Exploit |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.