Unlock underage blocked app without support interaction using airplane mode
Low
T
Tools for Humanity
Submitted None
Actions:
Reported by
polem4rch
Vulnerability Details
Technical details and impact analysis
## Summary:
Dear Worldcoin,
When using the iOS app i modified the dob on the app for an underage and the account got locked, and the app wouldnt allow me to do anything but talk to support to request the account unlock, however, by using airplane mode, theres another option that is enabled for the user to do it by itself using a passport.
Let me be perfectly clear, i couldnt finish the poc because the app asks for a scan on my passport RFID and Argentinian passports (where mine is from) have been reported to have issues at this, and the passport RFID doesnt work, you will see the VIDEO POC scan tries to do it and didnt work, so ive stopped trying.
Also about the vulnerability, when the users are able to unlock the accounts using a passport im not sure if this is a bad thing, unless,
1. This isnt supposed to happend and thats why youve placed support in first place
Steps:
1. Change the user dob on the app for an underage individual like 01/01/2015
2. Close and open the app
3. The app will request the users to contact support
4. Repeat step 2 multiple times (everytime the app asks to contact support)
5. Close the app
6. Enable airplane mode
7. Open the app
7. Disable airplane mode
8. Click on initiate government verification
9. Start process
VIDEO POC:
{F4331076}
Remediation: Make sure anytime the app regains connection the app resets?
Let me know if anything,
Regards,
Polem4rch
## Impact
Any user can bypass the support requirement to unlock the account, and do it by itself
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$300.00
Submitted
Weakness
Business Logic Errors