CVE-2018-19937
·1 min·
0
·
0
·
vlc
ios
vdp
A local, authenticated attacker can bypass the passcode in the VideoLAN VLC media player app before 3.1.5 for iOS by opening a URL and turning the phone.
- Product: VLC for Mobile IOS
- Vendor: VideoLAN/Open Source
- Software Version: 3.1.4 Below Category: Permissions, Privileges, and Access Control (CWE-264)
- Vendor Notified: 2018-11-26 11:00 PM
- Patched: 2018-12-21
- Disclosed: 2019-01-01
- Researcher(s): Christian Angel
- CVE: 2018-19937
References