VYPR
Medium severity4.6NVD Advisory· Published Apr 2, 2017· Updated May 13, 2026

CVE-2017-2399

CVE-2017-2399

Description

Physically proximate attackers can read the iOS pasteboard because its encryption key is derived only from the hardware UID, not the user passcode.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Physically proximate attackers can read the iOS pasteboard because its encryption key is derived only from the hardware UID, not the user passcode.

Vulnerability

The pasteboard in iOS versions prior to 10.3 on iPhone 5 and later, iPad 4th generation and later, and iPod touch 6th generation and later encrypts its data using a key derived solely from the hardware UID (unique identifier) rather than from a combination of the hardware UID and the user’s passcode. This design flaw means the pasteboard contents are accessible without authentication when an attacker has physical proximity to the device [1].

Exploitation

To exploit this vulnerability, an attacker must be physically proximate to the target device—typically within arm’s reach—and gain unauthorized physical access to the unlocked device or bypass the lock screen through another method. The attacker does not need to know the user’s passcode because the encryption key does not incorporate the passcode. By extracting the hardware UID (which is accessible from the device’s firmware), the attacker can derive the encryption key and decrypt the pasteboard data [1].

Impact

A successful attacker can read all current and potentially previously copied content stored on the pasteboard, which may include sensitive information such as passwords, credit card numbers, personal messages, or authentication tokens. This represents a breach of confidentiality, with the attacker operating at the user’s privilege level but without requiring the user’s passcode [1].

Mitigation

Apple released iOS 10.3 on March 27, 2017, which addresses the issue by modifying the pasteboard encryption to incorporate the user’s passcode into the key derivation. Users should update to iOS 10.3 or later to mitigate the vulnerability. There is no known workaround for unpatched devices [1].

AI Insight generated on May 22, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.