The Lock Screen component in Apple iOS before 8.3 does not properly enforce the limit on incorrect passcode-authentication attempts, which makes it easier for physically proximate attackers to obtain access by making many passcode guesses.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1108
Reference (s):
- APPLE:APPLE-SA-2015-04-08-3
- URL: http://lists.apple.com/archives/security-announce/2015/Apr/msg00002.html
- BID:73978
- URL: http://www.securityfocus.com/bid/73978
- https://support.apple.com/HT204661