CVE-2014-2019
MEDIUMiPhone OS < 7.1 - Unauthenticated iCloud Account Hijack via Blank Description Bypass
Title source: llmDescription
The iCloud subsystem in Apple iOS before 7.1 allows physically proximate attackers to bypass an intended password requirement, and turn off the Find My iPhone service or complete a Delete Account action and then associate this service with a different Apple ID account, by entering an arbitrary iCloud Account Password value and a blank iCloud Account Description value.
References (3)
Core 3
Core References
Third Party Advisory x_refsource_misc
http://news.softpedia.com/news/Major-iOS-7-Security-Flaw-Discovered-Video-425011.shtml
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT6162
Exploit, Third Party Advisory x_refsource_misc
http://www.youtube.com/watch?v=QnPk4RRWjic
Scores
CVSS v3
4.6
EPSS
0.0046
EPSS Percentile
37.7%
Attack Vector
PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Details
CWE
CWE-264
Status
published
Products (1)
apple/iphone_os
< 7.1
Published
Feb 18, 2014
Tracked Since
Feb 18, 2026