Vulnerability in iCloud behind celebrity nude photos leak?

September 2, 2014

Andrey Belenko and Alexey Troshichev have presented their concept program for breaking iCloud password on DefCon Russia a few days ago. It uses vulnerability in the Find My iPhone function that allows attacker to try to gues the password undefinitely allowing for brute force attacks. Since the password for Find My iPhone gives full access to the iCloud account, the hacker may have used this way to break to the celebrities‘ iClouds and stole their private photos. The vulnerability has been fixed by Apple in the meantime.

