A logic issue was addressed with improved checks. This issue is fixed in iOS 18.6 and iPadOS 18.6. Passcode may be read aloud by VoiceOver.
In iOS and iPadOS systems before version 18.6, a logic error (CWE-261) was discovered consisting of improper storage or handling of the screen lock code. The VoiceOver accessibility feature, designed to assist visually impaired persons, could read the passcode aloud under certain conditions. Apple indicates that the problem was fixed by introducing improved verification mechanisms.
An attacker or person in the vicinity of the device can hear the screen lock code read aloud by VoiceOver, enabling unauthorized access to the device and data stored on it.
Devices should be updated to iOS 18.6 and iPadOS 18.6, in which Apple has implemented a fix eliminating this issue. Detailed information is available on the Apple support page: https://support.apple.com/en-us/124147
Apple iOS before version 18.6 and Apple iPadOS before version 18.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:HApple iPadOS
OSApple< 18.6Apple iOS
OSApple< 18.6
Related vulnerabilities
Apple iOS/iPadOS/macOS — out-of-bounds write przy przetwarzaniu obrazu
Apple — memory corruption (RCE) w przetwarzaniu strumieni audio
Apple: Obejście Pointer Authentication w iOS, macOS i innych platformach
Apple WebKit: out-of-bounds write umożliwiający ucieczkę z sandbox przeglądarki
Use-after-free w Apple iOS/iPadOS/macOS — privilege escalation przez aplikację