CVE-2014-4451: Apple iPhone OS

High severity, CVSS 7.2. EPSS: 0.4% chance of exploitation in the next 30 days.

Apple iOS before 8.1.1 does not properly enforce the failed-passcode limit, which makes it easier for physically proximate attackers to bypass the lock-screen protection mechanism via a series of guesses.

Affected products

  • Apple iPhone OS: up to and including 8.1; version 8.0 only; version 8.0.1 only; version 8.0.2 only

Published 2014-11-18. Last modified 2026-06-17.