First published: Thu Mar 29 2018(Updated: )
Find My iPhone. A state management issue existed when restoring from a back up. This issue was addressed through improved state checking during restore.
Credit: Viljami Vastamäki product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS and iPadOS | <11.3 | 11.3 |
iPhone OS | <11.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2018-4172 is a vulnerability that affects certain Apple products running iOS before 11.3. It involves the "Find My iPhone" component, allowing attackers to bypass the iCloud password requirement for disabling the feature.
CVE-2018-4172 allows physically proximate attackers to bypass the iCloud password requirement for disabling the "Find My iPhone" feature on affected Apple devices.
The severity of CVE-2018-4172 is medium, with a CVSS severity score of 4.6.
iOS versions before 11.3 are affected by CVE-2018-4172.
Yes, updating to iOS version 11.3 or later will address the vulnerability.