Settings in Apple iOS before 7.1.2 allows physically proximate attackers to bypass an intended iCloud password requirement, and turn off the Find My iPhone service, by leveraging incorrect state management.
2014-07-01T10:17:26.250
2025-04-12T10:46:40.837
Deferred
CVSSv2: 4.6 (MEDIUM)
AV:L/AC:L/Au:N/C:P/I:P/A:P
3.9
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | apple | iphone_os | ≤ 7.1.1 | Yes |
| Operating System | apple | iphone_os | 7.0 | Yes |
| Operating System | apple | iphone_os | 7.0.1 | Yes |
| Operating System | apple | iphone_os | 7.0.2 | Yes |
| Operating System | apple | iphone_os | 7.0.3 | Yes |
| Operating System | apple | iphone_os | 7.0.4 | Yes |
| Operating System | apple | iphone_os | 7.0.5 | Yes |
| Operating System | apple | iphone_os | 7.0.6 | Yes |
| Operating System | apple | iphone_os | 7.1 | Yes |