PT-2018-11821 · Line · Line

Parameth Eimsongsak

+1

·

Published

2018-08-16

·

Updated

2024-08-05

·

CVE-2018-13434

CVSS v3.1

6.3

Medium

VectorAV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LINE application version 8.8.0 for iOS
Description An issue in the LINE application allows authentication bypass by overriding the LAContext return Boolean value to be "true" because the kSecAccessControlUserPresence protection mechanism is not used. This enables an attacker to authenticate with an arbitrary fingerprint. The vendor notes that this issue is not considered significant within their threat model, specifically excluding iOS devices that have been jailbroken.
Recommendations For version 8.8.0, consider disabling the Biometric (TouchID) validation feature until a patch is available to prevent potential authentication bypass.

Exploit

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2018-13434

Affected Products

Line