[GH-ISSUE #258] [Bug] Unlimited Pin / Fingerprint Unlock Tries #6576

Closed
opened 2026-04-10 22:45:14 -05:00 by GiteaMirror · 1 comment
Owner

Originally created by @edsimpsons83 on GitHub (Jan 18, 2018).
Original GitHub issue: https://github.com/bitwarden/android/issues/258

I am classifying this as a bug since Apple and Google do (e.g. Apple CVE-2014-4451 - Unlimited incorrect pin attempts on iOS). Currently, if a pin unlock or fingerprint unlock is set on the mobile app, a user or attacker is allowed unlimited attempts to try and unlock the Bitwarden vault instead of being capped at a reasonable amount e.g. 5 before reprompting for the master password.

Originally created by @edsimpsons83 on GitHub (Jan 18, 2018). Original GitHub issue: https://github.com/bitwarden/android/issues/258 I am classifying this as a bug since Apple and Google do (e.g. Apple CVE-2014-4451 - Unlimited incorrect pin attempts on iOS). Currently, if a pin unlock or fingerprint unlock is set on the mobile app, a user or attacker is allowed unlimited attempts to try and unlock the Bitwarden vault instead of being capped at a reasonable amount e.g. 5 before reprompting for the master password.
Author
Owner

@kspearrin commented on GitHub (Jan 18, 2018):

Thanks. We already have this slated as a fix in next version with a limit of 10 attempts.

<!-- gh-comment-id:358710163 --> @kspearrin commented on GitHub (Jan 18, 2018): Thanks. We already have this slated as a fix in next version with a limit of 10 attempts.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/android#6576