VYPR
Unrated severityNVD Advisory· Published Nov 18, 2013· Updated Apr 29, 2026

CVE-2013-5193

CVE-2013-5193

Description

A local attacker can complete App or In-App purchases in iOS <7.0.4 without entering the Apple ID password, abusing previously stored credentials.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A local attacker can complete App or In-App purchases in iOS <7.0.4 without entering the Apple ID password, abusing previously stored credentials.

Vulnerability

In Apple iOS prior to version 7.0.4, the App Store component fails to properly enforce a password requirement at transaction time. When a user has previously entered their Apple ID credentials, subsequent App purchases or In-App purchases on the same device can be completed without re‑entering the password. Affected versions are iOS 7.x before 7.0.4; the issue was addressed in iOS 7.0.4 [1].

Exploitation

An attacker with physical access to an unlocked iOS device (or a user who has already signed into the App Store) can start a purchase in the App Store. Because the previous authentication token is reused, the purchase proceeds without a password prompt. No additional network access or special privileges are needed beyond local device access [1].

Impact

A local user can complete unauthorized App or In‑App purchases, effectively spending the account owner’s funds. While the attacker does not gain credentials or system-level control, the financial impact and breach of purchase authorization constitute a significant integrity violation of the transaction process [1].

Mitigation

Apple released iOS 7.0.4 on 14 November 2013, which enforces the password requirement at purchase time. Users should update all compatible devices (iPhone 4 and later, iPod touch 5th generation and later, iPad 2 and later) to iOS 7.0.4 or newer. No workaround is documented for unpatched devices [1].

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

5
  • cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*range: <=7.0.3
    • cpe:2.3:o:apple:iphone_os:7.0:*:*:*:*:*:*:*
    • cpe:2.3:o:apple:iphone_os:7.0.1:*:*:*:*:*:*:*
    • cpe:2.3:o:apple:iphone_os:7.0.2:*:*:*:*:*:*:*
  • Apple Inc./iOSllm-fuzzy
    Range: <7.0.4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.