Lock Screen can be bypassed on iOS #47

Closed
opened 2025-11-07 08:24:35 -06:00 by GiteaMirror · 4 comments
Owner

Originally created by @atheler on GitHub (Apr 28, 2017).

It is possible to bypass entering the master password by closing the app (home button double-click / app switching) and then restarting it. This is only possible with Auto-Lock set to anything but „intermediate“ and not when the app was locked manually.

Bitwarden Version 1.0.0 (7), iOS 10.3.1

Originally created by @atheler on GitHub (Apr 28, 2017). It is possible to bypass entering the master password by closing the app (home button double-click / app switching) and then restarting it. This is only possible with Auto-Lock set to anything but „intermediate“ and not when the app was locked manually. Bitwarden Version 1.0.0 (7), iOS 10.3.1
Author
Owner

@kspearrin commented on GitHub (Apr 28, 2017):

Testing and I am not able to reproduce. Are you waiting past the amount of time selected from the option?

@kspearrin commented on GitHub (Apr 28, 2017): Testing and I am not able to reproduce. Are you waiting past the amount of time selected from the option?
Author
Owner

@atheler commented on GitHub (Apr 28, 2017):

Yes, I am waiting past the amount of time selected (e.g. 1 minute). The app will then also correctly ask me for my password. However, in this state it is then possible to restart the app. After this it will not ask for my password anymore and I can then simply access my keychain.

A friend of mine was also able to reproduce this bug on his iPhone.

@atheler commented on GitHub (Apr 28, 2017): Yes, I am waiting past the amount of time selected (e.g. 1 minute). The app will then also correctly ask me for my password. However, in this state it is then possible to restart the app. After this it will not ask for my password anymore and I can then simply access my keychain. A friend of mine was also able to reproduce this bug on his iPhone.
Author
Owner

@kspearrin commented on GitHub (Apr 28, 2017):

Ok, I got it to work now. It requires you to restart from the actual lock screen. Thanks.

@kspearrin commented on GitHub (Apr 28, 2017): Ok, I got it to work now. It requires you to restart from the actual lock screen. Thanks.
Author
Owner

@kspearrin commented on GitHub (Apr 28, 2017):

This should be resolved in the next version.

@kspearrin commented on GitHub (Apr 28, 2017): This should be resolved in the next version.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/android#47