VYPR
Low severity2.4NVD Advisory· Published Nov 13, 2017· Updated May 13, 2026

CVE-2017-13844

CVE-2017-13844

Description

A physically proximate attacker can view arbitrary photos on a locked iPhone running iOS < 11.1 via the Reply With Message action in Messages.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A physically proximate attacker can view arbitrary photos on a locked iPhone running iOS < 11.1 via the Reply With Message action in Messages.

Vulnerability

The vulnerability resides in the "Messages" component of iOS versions prior to 11.1. When the device is locked, a physically proximate attacker can leverage the lock-screen's "Reply With Message" action to view arbitrary photos stored on the device. The issue was addressed in iOS 11.1, which was released on October 31, 2017 [1].

Exploitation

An attacker must have physical proximity to an unlocked device that is in the lock-screen state (i.e., the device is locked but notifications or quick actions are accessible). The specific sequence of steps involves using the device's lock-screen Reply With Message feature, which bypasses the normal authentication check for photo viewing.

Impact

A successful exploit allows a physically proximate attacker to view arbitrary photos that are stored on the device, bypassing the lock-screen protection. This leads to an unauthorized disclosure of visual information (confidentiality breach) without requiring the device passcode.

Mitigation

Users should update to iOS 11.1 or later, which was released on October 31, 2017 and addresses this issue [1]. No workaround is described for unpatched versions; maintaining physical control of the device is the only alternative until the patch is applied.

AI Insight generated on May 22, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.