PT-2018-11821 · Line · Line
Parameth Eimsongsak
+1
·
Published
2018-08-16
·
Updated
2024-08-05
·
CVE-2018-13434
CVSS v3.1
6.3
Medium
| Vector | AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
LINE application version 8.8.0 for iOS
Description
An issue in the LINE application allows authentication bypass by overriding the
LAContext return Boolean value to be "true" because the kSecAccessControlUserPresence protection mechanism is not used. This enables an attacker to authenticate with an arbitrary fingerprint. The vendor notes that this issue is not considered significant within their threat model, specifically excluding iOS devices that have been jailbroken.Recommendations
For version 8.8.0, consider disabling the Biometric (TouchID) validation feature until a patch is available to prevent potential authentication bypass.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Line