CVE-2018-12271: An issue was discovered in the com.getdropbox.Dropbox app 100.2 for iOS. The LAContext class for Biometric (TouchID) val
infovulnerability
security
Summary
A security flaw in Dropbox version 100.2 for iOS allows attackers to bypass fingerprint authentication (TouchID, which uses biometric scanning) by manipulating the authentication system to always return 'true' rather than actually verifying the user's fingerprint. The vulnerability exists because the app doesn't use proper protection mechanisms to ensure the fingerprint validation is genuine, though Dropbox stated this is not a concern for their security model since it only affects jailbroken devices (iPhones that have been modified to remove Apple's security restrictions).
Vulnerability Details
CVSS Score
6.9
EPSS (30-day exploit probability)
EPSS: 0.0%
Classification
Attack SophisticationModerate
Original source: https://nvd.nist.gov/vuln/detail/CVE-2018-12271
First tracked: February 15, 2026 at 08:52 PM
Classified by LLM (prompt v3) · confidence: 95%