First published: Tue Jun 22 2010(Updated: )
Passcode Lock in Apple iOS before 4 on the iPhone and iPod touch does not properly handle alert-based unlocks in conjunction with subsequent Remote Lock operations through MobileMe, which allows physically proximate attackers to bypass intended passcode requirements via unspecified vectors.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPhone OS | <4.0 | |
Apple iPod touch | ||
Apple iPhone OS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-1754 is considered a high severity vulnerability as it allows attackers to bypass passcode requirements.
CVE-2010-1754 affects Apple iOS versions prior to 4.0.
To fix CVE-2010-1754, users should upgrade their iOS to version 4.0 or later.
The attack vector for CVE-2010-1754 involves exploiting the alert-based unlock feature in conjunction with Remote Lock operations.
CVE-2010-1754 primarily impacts the iPhone; however, the iPod touch is not affected by this vulnerability.