← Vulnerability feed

Vulnerability record · CVE-2008-3631 · published 11 September 2008

CVE-2008-3631: Apple ipod touch permissions and access controls vulnerability

Apple · Ipod Touch

Application Sandbox in Apple iPod touch 2.0 through 2.0.2, and iPhone 2.0 through 2.0.2, does not properly isolate third-party applications, which allows attackers to read arbitrary files in a third-party application's sandbox via a different third-party application.

7.1 CVSS 2.0 High EPSS 1.9% · top 21.0% CWE-264 · Permissions and access controls
7.1CVSS 2.0 base score
1.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
20References
16 Jun 2026Last modified by NVD

Description

Application Sandbox in Apple iPod touch 2.0 through 2.0.2, and iPhone 2.0 through 2.0.2, does not properly isolate third-party applications, which allows attackers to read arbitrary files in a third-party application's sandbox via a different third-party application.

AV:N/AC:M/Au:N/C:C/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-3631 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2009-1725Apple safari vulnerabilityWebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms; KHTML in kdelibs in…EPSS 6.2%9.3CVE-2009-1701Apple safari vulnerabilityUse-after-free vulnerability in the JavaScript DOM implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS fo…EPSS 7.7%9.3CVE-2009-1698Apple safari code injection vulnerabilityWebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not initialize a pointer during h…EPSS 8.5%9.3CVE-2008-3632Apple iphone vulnerabilityUse-after-free vulnerability in WebKit in Apple iPod touch 1.1 through 2.0.2, and iPhone 1.0 through 2.0.2, allows remote attackers to execute arbitr…EPSS 6.0%7.8CVE-2009-1683Apple iphone os vulnerabilityThe Telephony component in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to cause a denial…EPSS 2.8%7.1CVE-2009-0959Apple iphone os improper input validation vulnerabilityThe MPEG-4 video codec in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to cause a denial …EPSS 2.5%7.1CVE-2009-1692Apple iphone os vulnerabilityWebKit before r41741, as used in Apple iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Safari, and other software, allows re…EPSS 4.2%6.8CVE-2009-2206Apple iphone os memory buffer overflow vulnerabilityMultiple heap-based buffer overflows in the AudioCodecs library in the CoreAudio component in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 …EPSS 4.6%

Source: NIST National Vulnerability Database (record CVE-2008-3631), CISA KEV, FIRST EPSS (scores of 2026-10-03). This page is refreshed as NVD updates the record.