Skip to content

[Bug] Unlimited Pin / Fingerprint Unlock Tries #258

@edsimpsons83

Description

@edsimpsons83

I am classifying this as a bug since Apple and Google do (e.g. Apple CVE-2014-4451 - Unlimited incorrect pin attempts on iOS). Currently, if a pin unlock or fingerprint unlock is set on the mobile app, a user or attacker is allowed unlimited attempts to try and unlock the Bitwarden vault instead of being capped at a reasonable amount e.g. 5 before reprompting for the master password.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions