Skip to content

CVE-2014-1267

The Configuration Profiles component in Apple iOS before 7.1 and Apple TV before 6.1 does not properly evaluate the expiration date of a mobile configuration profile, which allows attackers to bypass intended access restrictions by using a profile after the date has passed.

View on NVD

Severity

N/A

EPSS

Probability of exploitation (next 30 days): 0.0022 (0.2%)
Percentile: 44.5%
EPSS: 2026-05-06

Affects

apple:tvosapple:iphone_os

Technical description

The Configuration Profiles component in Apple iOS before 7.1 and Apple TV before 6.1 does not properly evaluate the expiration date of a mobile configuration profile, which allows attackers to bypass intended access restrictions by using a profile after the date has passed.

Published: 3/14/2014, 10:55:05 AM
Last modified: 5/6/2026, 10:30:45 PM

References

HomeEventsBlogResourcesTeam