Unrated severityNVD Advisory· Published Nov 18, 2013· Updated Jun 16, 2026
CVE-2013-5193
CVE-2013-5193
Description
The App Store component in Apple iOS before 7.0.4 does not properly enforce an intended transaction-time password requirement, which allows local users to complete a (1) App purchase or (2) In-App purchase by leveraging previous entry of Apple ID credentials.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*range: <=7.0.3
- cpe:2.3:o:apple:iphone_os:7.0.1:*:*:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:7.0.2:*:*:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:7.0:*:*:*:*:*:*:*
- Range: <7.0.4
Patches
Vulnerability mechanics
References
2- lists.apple.com/archives/security-announce/2013/Nov/msg00000.htmlnvdVendor Advisory
- support.apple.com/kb/HT6058nvdVendor Advisory
News mentions
0No linked articles in our index yet.