Security Advisory – CVE-2018-19937

Product: VLC for Mobile IOS
Vendor: VideoLAN/Open Source Software
Version: 3.1.4 Below
Category: Permissions, Privileges, and Access Control (CWE-264)
Vendor Notified: 2018-11-26 11:00 PM
Patched: 2018-12-21
Disclosed: 2019-01-01
Researcher(s): Christian Angel
CVE: 2018-19937

Summary

A local, authenticated attacker can bypass the passcode in the VideoLAN VLC media player app before 3.1.5 for iOS by opening a URL and turning the phone.

Solution

Update the application to the latest version

References

https://apps.apple.com/ms/app/vlc-for-mobile/id650377962

https://github.com/videolan/vlc-ios/pull/178/commits/d84d7c0a94eb7fba202d2c5fc3739276d2d3986f

https://nvd.nist.gov/vuln/detail/CVE-2018-19937

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Google photo

You are commenting using your Google account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s

This site uses Akismet to reduce spam. Learn how your comment data is processed.