CVE-2021-1863

LOW

iPadOS < 14.5 - Improper Authentication via NFC Tag Action

Title source: llm
STIX 2.1

Description

An issue existed with authenticating the action triggered by an NFC tag. The issue was addressed with improved action authentication. This issue is fixed in iOS 14.5 and iPadOS 14.5. A person with physical access to an iOS device may be able to place phone calls to any phone number.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT212317

Scores

CVSS v3 2.4
EPSS 0.0029
EPSS Percentile 20.1%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-287
Status published
Products (2)
apple/ipados < 14.5
apple/iphone_os < 14.5
Published Sep 08, 2021
Tracked Since Feb 18, 2026