Biometric Authentication Bypass in Dropbox App for iOS
CVE-2018-12271
6.4MEDIUM
What is CVE-2018-12271?
A security issue in the Dropbox app for iOS (version 100.2) enables an attacker to bypass biometric authentication via the LAContext class. This occurs because the kSecAccessControlUserPresence method is not utilized, leading to the potential for unauthorized access with a falsified 'true' return value for authentication. While the vendor has stated that this vulnerability is not within the scope of their threat model, it poses a risk on jailbroken iOS devices where the standard security mechanisms are compromised.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
