← Vulnerability feed

Vulnerability record · CVE-2008-3876 · published 2 September 2008

CVE-2008-3876: Apple iphone permissions and access controls vulnerability

Apple · Iphone

Apple iPhone 2.0.2, in some configurations, allows physically proximate attackers to bypass intended access restrictions, and obtain sensitive information or make arbitrary use of the device, via an Emergency Call tap and a Home double-tap, followed by a tap of any contact's blue arrow.

1.9 CVSS 2.0 Low EPSS 0.46% · top 62.8% CWE-264 · Permissions and access controls
1.9CVSS 2.0 base score
0.46%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Apple iPhone 2.0.2, in some configurations, allows physically proximate attackers to bypass intended access restrictions, and obtain sensitive information or make arbitrary use of the device, via an Emergency Call tap and a Home double-tap, followed by a tap of any contact's blue arrow.

AV:L/AC:M/Au:N/C:P/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-3876 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2008-3632Apple iphone vulnerabilityUse-after-free vulnerability in WebKit in Apple iPod touch 1.1 through 2.0.2, and iPhone 1.0 through 2.0.2, allows remote attackers to execute arbitr…EPSS 6.0%7.5CVE-2007-3753Apple iphone improper input validation vulnerabilityApple iPhone 1.1.1, with Bluetooth enabled, allows physically proximate attackers to cause a denial of service (application termination) and execute …EPSS 2.8%6.5CVE-2022-22592Apple safari vulnerabilityA logic issue was addressed with improved state management. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, mac…EPSS 1.6%5.0CVE-2008-3950Apple iphone vulnerabilityOff-by-one error in the _web_drawInRect:withFont:ellipsis:alignment:measureOnly function in WebKit in Safari in Apple iPhone 1.1.4 and 2.0 and iPod t…EPSS 7.1%4.6CVE-2008-0034Apple iphone vulnerabilityUnspecified vulnerability in Passcode Lock in Apple iPhone 1.0 through 1.1.2 allows users with physical access to execute applications without enteri…EPSS 0.36%4.3CVE-2007-3754Apple iphone improper authentication vulnerabilityMail in Apple iPhone 1.1.1, when using SSL, does not warn the user when the mail server changes or is not trusted, which might allow remote attackers…EPSS 1.8%4.3CVE-2007-3755Apple iphone improper input validation vulnerabilityMail in Apple iPhone 1.1.1 allows remote user-assisted attackers to force the iPhone user to make calls to arbitrary telephone numbers via a "tel:" l…EPSS 2.0%1.2CVE-2008-4593Apple iphone information exposure vulnerabilityApple iPhone 2.1 with firmware 5F136, when Require Passcode is enabled and Show SMS Preview is disabled, allows physically proximate attackers to obt…EPSS 0.32%

Source: NIST National Vulnerability Database (record CVE-2008-3876), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.