First published: Fri Apr 10 2015(Updated: )
The Lock Screen component in Apple iOS before 8.3 does not properly implement the erasure feature for incorrect passcode-authentication attempts, which makes it easier for physically proximate attackers to obtain access by making many passcode guesses.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPhone OS | <=8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1107 is classified as a medium severity vulnerability due to the potential for unauthorized access through passcode guesswork.
To fix CVE-2015-1107, it is recommended to update your iOS device to version 8.3 or later.
CVE-2015-1107 affects Apple iOS versions prior to 8.3 on iPhone and other compatible devices.
Users with iOS devices running versions earlier than 8.3 are impacted by CVE-2015-1107.
CVE-2015-1107 involves improper implementation of the lock screen erasure feature, allowing attackers to guess passcodes more easily.