First published: Tue Jul 01 2014(Updated: )
Lockdown in Apple iOS before 7.1.2 does not properly verify data from activation servers, which makes it easier for physically proximate attackers to bypass the Activation Lock protection mechanism via unspecified vectors.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
iPhone OS | <=7.1.1 | |
iPhone OS | =7.0 | |
iPhone OS | =7.0.1 | |
iPhone OS | =7.0.2 | |
iPhone OS | =7.0.3 | |
iPhone OS | =7.0.4 | |
iPhone OS | =7.0.5 | |
iPhone OS | =7.0.6 | |
iPhone OS | =7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-1360 is considered to have a medium severity due to its potential to bypass Activation Lock on affected devices.
CVE-2014-1360 affects Apple iOS versions prior to 7.1.2, specifically versions 7.0 to 7.1.1.
To fix CVE-2014-1360, you should update your device to iOS version 7.1.2 or later.
CVE-2014-1360 can allow physically proximate attackers to bypass the Activation Lock protection, compromising device security.
There are no known mitigations for CVE-2014-1360 other than updating to a non-vulnerable version of iOS.