Product: VLC for Mobile IOS
Vendor: VideoLAN/Open Source Software
Version: 3.1.4 Below
Category: Permissions, Privileges, and Access Control (CWE-264)
Vendor Notified: 2018-11-26 11:00 PM
Researcher(s): Christian Angel
A local, authenticated attacker can bypass the passcode in the VideoLAN VLC media player app before 3.1.5 for iOS by opening a URL and turning the phone.
Update the application to the latest version