Lock Screen Vulnerability Allows Unauthorized Access to Carrier Account Information and Settings

Lock Screen Vulnerability Allows Unauthorized Access to Carrier Account Information and Settings

CVE-2022-22652 · MEDIUM Severity

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

The GSMA authentication panel could be presented on the lock screen. The issue was resolved by requiring device unlock to interact with the GSMA authentication panel. This issue is fixed in iOS 15.4 and iPadOS 15.4. A person with physical access may be able to view and modify the carrier account information and settings from the lock screen.

Learn more about our Cis Benchmark Audit For Apple Ios.