Apple iOS Screen Time & Parental Controls Bypass
High Severity
CWE-284: Authorization Bypass
Reported to Apple
Security Advisory & Proof of Concept (PoC)
A logic flaw in iOS/iPadOS allows a restricted child account to completely bypass Screen Time limits and parental controls by triggering a local device wipe through the native Find My application without requiring parental passcode authentication.
📄 Download Technical PoC (PDF)
🇬🇧 Technical Summary
- Affected Feature: Screen Time, Family Sharing, Find My Framework
- Vulnerability: Local Erase command in Find My executes immediately without prompting for the Screen Time passcode.
- Impact: Device reboots completely wiped, allowing the child to configure it as a new unmanaged device.
🛠️ Steps to Reproduce
- Open the native Find My app on the restricted device.
- Navigate to the Devices tab.
- Select the local device from the list.
- Scroll down and tap Erase This Device.
- Confirm the action. The device executes a full factory reset.
🇵🇱 Opis po polsku
Luka w logice systemowej iOS/iPadOS pozwala dziecku na natychmiastowe usunięcie wszelkich blokad Czasu przed ekranem. Wystarczy uruchomić aplikację "Znajdź", wybrać swój telefon i kliknąć "Wymaż to urządzenie". System nie prosi o kod rodzica i resetuje telefon do ustawień fabrycznych.
Disclaimer: This documentation is published for educational and responsible disclosure purposes only.