First published: Tue Jan 29 2013(Updated: )
Identity Services in Apple iOS before 6.1 does not properly handle validation failures of AppleID certificates, which might allow physically proximate attackers to bypass authentication by leveraging an incorrect assignment of an empty string value to an AppleID.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPhone OS | <=6.0.2 | |
Apple iPhone OS | =6.0 | |
Apple iPhone OS | =6.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-0963 has a moderate severity rating due to its potential to allow attackers to bypass AppleID authentication.
To fix CVE-2013-0963, users should update their iOS devices to version 6.1 or later.
CVE-2013-0963 affects Apple iOS versions up to and including 6.0.2.
CVE-2013-0963 involves a physical proximity attack that exploits improper validation of AppleID certificates.
Yes, CVE-2013-0963 can affect devices even if AppleID is not actively in use by allowing bypass of authentication.