PT-2024-12916 · Apple · Ipados+1

Zhice Yang

·

Published

2024-01-10

·

Updated

2024-01-17

·

CVE-2023-41069

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions iOS versions prior to 17 iPadOS versions prior to 17
Description The issue allows a 3D model constructed to look like the enrolled user to authenticate via Face ID, due to inadequate anti-spoofing models. This has been addressed by improving Face ID anti-spoofing models.
Recommendations For iOS versions prior to 17, update to iOS 17 to fix the issue. For iPadOS versions prior to 17, update to iPadOS 17 to fix the issue.

Fix

Authentication Bypass by Spoofing

Weakness Enumeration

Related Identifiers

CVE-2023-41069

Affected Products

Ios
Ipados