Loading HuntDB...

Unlock underage blocked app without support interaction using airplane mode

Low
T
Tools for Humanity
Submitted None
Reported by polem4rch

Vulnerability Details

Technical details and impact analysis

Business Logic Errors
## Summary: Dear Worldcoin, When using the iOS app i modified the dob on the app for an underage and the account got locked, and the app wouldnt allow me to do anything but talk to support to request the account unlock, however, by using airplane mode, theres another option that is enabled for the user to do it by itself using a passport. Let me be perfectly clear, i couldnt finish the poc because the app asks for a scan on my passport RFID and Argentinian passports (where mine is from) have been reported to have issues at this, and the passport RFID doesnt work, you will see the VIDEO POC scan tries to do it and didnt work, so ive stopped trying. Also about the vulnerability, when the users are able to unlock the accounts using a passport im not sure if this is a bad thing, unless, 1. This isnt supposed to happend and thats why youve placed support in first place Steps: 1. Change the user dob on the app for an underage individual like 01/01/2015 2. Close and open the app 3. The app will request the users to contact support 4. Repeat step 2 multiple times (everytime the app asks to contact support) 5. Close the app 6. Enable airplane mode 7. Open the app 7. Disable airplane mode 8. Click on initiate government verification 9. Start process VIDEO POC: {F4331076} Remediation: Make sure anytime the app regains connection the app resets? Let me know if anything, Regards, Polem4rch ## Impact Any user can bypass the support requirement to unlock the account, and do it by itself

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Bounty

$300.00

Submitted

Weakness

Business Logic Errors