Description
AirKeyboard iOS App 1.0.5 contains a missing authentication vulnerability that allows unauthenticated attackers to type arbitrary keystrokes directly into the victim's iOS device in real-time without user interaction, resulting in full remote input control.
Problem types
CWE-306: Missing Authentication for Critical Function
Product status
1.0.5
Credits
Chokri Hammedi
References
www.exploit-db.com/exploits/52333 (Exploit Database Entry 52333)
airkeyboardapp.com (AirKeyboard Homepage)
apps.apple.com/us/app/air-keyboard/id6463187929 (Apple App Store Link)
www.vulncheck.com/...oard-ios-app-105-remote-input-injection