CVE-2017-13844
Description
A physically proximate attacker can view arbitrary photos on a locked iPhone running iOS < 11.1 via the Reply With Message action in Messages.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A physically proximate attacker can view arbitrary photos on a locked iPhone running iOS < 11.1 via the Reply With Message action in Messages.
Vulnerability
The vulnerability resides in the "Messages" component of iOS versions prior to 11.1. When the device is locked, a physically proximate attacker can leverage the lock-screen's "Reply With Message" action to view arbitrary photos stored on the device. The issue was addressed in iOS 11.1, which was released on October 31, 2017 [1].
Exploitation
An attacker must have physical proximity to an unlocked device that is in the lock-screen state (i.e., the device is locked but notifications or quick actions are accessible). The specific sequence of steps involves using the device's lock-screen Reply With Message feature, which bypasses the normal authentication check for photo viewing.
Impact
A successful exploit allows a physically proximate attacker to view arbitrary photos that are stored on the device, bypassing the lock-screen protection. This leads to an unauthorized disclosure of visual information (confidentiality breach) without requiring the device passcode.
Mitigation
Users should update to iOS 11.1 or later, which was released on October 31, 2017 and addresses this issue [1]. No workaround is described for unpatched versions; maintaining physical control of the device is the only alternative until the patch is applied.
AI Insight generated on May 22, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <11.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.securityfocus.com/bid/102099nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1039703nvdThird Party AdvisoryVDB Entry
- support.apple.com/HT208222nvdVendor Advisory
News mentions
0No linked articles in our index yet.