First published: Fri Apr 10 2015(Updated: )
The Lock Screen component in Apple iOS before 8.3 does not properly enforce the limit on incorrect passcode-authentication attempts, which makes it easier for physically proximate attackers to obtain access by making many passcode guesses.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPhone OS | <=8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1108 is classified as moderate severity due to its potential for unauthorized access through brute-force attacks on passcodes.
To mitigate CVE-2015-1108, update your Apple iOS device to version 8.3 or later, which addresses this vulnerability.
CVE-2015-1108 affects Apple iOS versions prior to 8.3, including all versions up to 8.2.
CVE-2015-1108 enables physical attackers to make numerous passcode guesses without being locked out, increasing the risk of unauthorized access.
Yes, CVE-2015-1108 poses a risk of data exposure as unauthorized users could gain access to sensitive information if they successfully guess the passcode.