PT-2018-11821 · Line · Line
Parameth Eimsongsak
+1
·
Publicado
2018-08-16
·
Atualizado
2024-08-05
·
CVE-2018-13434
CVSS v3.1
6.3
Média
| Vetor | AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
LINE application version 8.8.0 for iOS
Description
An issue in the LINE application allows authentication bypass by overriding the
LAContext return Boolean value to be "true" because the kSecAccessControlUserPresence protection mechanism is not used. This enables an attacker to authenticate with an arbitrary fingerprint. The vendor notes that this issue is not considered significant within their threat model, specifically excluding iOS devices that have been jailbroken.Recommendations
For version 8.8.0, consider disabling the Biometric (TouchID) validation feature until a patch is available to prevent potential authentication bypass.
Exploit
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Line