CVE-2018-19937
Severity CVSS v4.0:
Pending analysis
Type:
CWE-287
Authentication Issues
Publication date:
31/12/2018
Last modified:
06/05/2025
Description
A local, authenticated attacker can bypass the passcode in the VideoLAN VLC media player app before 3.1.5 for iOS by opening a URL and turning the phone.
Impact
Base Score 3.x
6.60
Severity 3.x
MEDIUM
Base Score 2.0
4.60
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:videolan:vlc_for_mobile:*:*:*:*:*:iphone_os:*:* | 3.1.5 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://github.com/videolan/vlc-ios/pull/178/commits/d84d7c0a94eb7fba202d2c5fc3739276d2d3986f
- https://itunes.apple.com/ms/app/vlc-for-mobile/id650377962?mt=8
- https://github.com/videolan/vlc-ios/pull/178/commits/d84d7c0a94eb7fba202d2c5fc3739276d2d3986f
- https://itunes.apple.com/ms/app/vlc-for-mobile/id650377962?mt=8



