
Cloud Vulnerability DB
A community-led vulnerabilities database
A disputed vulnerability was discovered in the LogMein LastPass Password Manager (com.lastpass.ilastpass) app version 4.8.11.2403 for iOS. The vulnerability allows bypassing the password authentication for unlocking by manipulating the authentication result through runtime manipulation, effectively allowing authentication with any arbitrary password. The vendor has indicated this is not considered an attack of interest within their threat model as it requires a jailbroken device (NVD).
The vulnerability affects the password authentication mechanism used for unlocking the LastPass vault. Through runtime manipulation, an attacker can force the authentication result to be true, bypassing the legitimate password verification process. The vulnerability has been assigned a CVSS v3.1 Base Score of 5.7 MEDIUM (Vector: CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N) and a CVSS v2.0 Base Score of 3.3 LOW (Vector: AV:L/AC:M/Au:N/C:P/I:P/A:N) (NVD).
If successfully exploited, an attacker with physical access to a jailbroken iOS device could bypass the LastPass vault's password authentication mechanism and gain unauthorized access to stored credentials and sensitive information (LastPass Vulnerabilities).
The vulnerability requires physical access to the device and a jailbroken iOS environment to perform the runtime manipulation. A proof-of-concept demonstration has been published showing the successful exploitation of this vulnerability (LastPass Vulnerabilities).
LastPass has disputed this vulnerability as it falls outside their threat model, which explicitly excludes jailbroken devices. No official patch has been released as the vendor considers the prerequisite of a jailbroken device to be beyond their security boundaries (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."