The iCloud subsystem in Apple iOS before 7.1 allows physically proximate attackers to bypass an intended password requirement, and turn off the Find My iPhone service or complete a Delete Account action and then associate this service with a different Apple ID account, by entering an arbitrary iCloud Account Password value and a blank iCloud Account Description value.
2014-02-18T11:55:17.027
2025-04-11T00:51:21.963
Deferred
CVSSv3.1: 4.6 (MEDIUM)
AV:L/AC:L/Au:N/C:N/I:C/A:N
3.9
6.9