First published: Fri Sep 18 2015(Updated: )
AppleKeyStore in Apple iOS before 9 allows physically proximate attackers to reset the count of incorrect passcode attempts via a device backup.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPhone OS | <=8.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-5850 is classified as a high severity vulnerability due to its potential to allow unauthorized access to user data.
To mitigate CVE-2015-5850, update your iOS device to version 9 or later to ensure the vulnerability is patched.
CVE-2015-5850 affects all versions of Apple iOS prior to 9, specifically those up to and including 8.4.1.
CVE-2015-5850 allows physically proximate attackers to reset the count of incorrect passcode attempts by taking advantage of device backups.
There is no effective workaround for CVE-2015-5850, and the only solution is to upgrade to a non-vulnerable version of iOS.