www.bgr.com Flaw in iOS 17.3 Stolen Device Protection Exposed
Article Content
Browse articles
- •iOS 17.3's Stolen Device Protection has a flaw allowing settings changes in familiar locations.
- •Users have a one-hour grace period to react to theft, but this can be exploited by thieves.
- •A workaround exists by disabling Significant Locations, but it reduces the feature's effectiveness.
iOS 17.3 introduced Stolen Device Protection, a feature designed to secure iPhones against theft. However, it has a flaw that allows thieves to change key settings if the device is stolen in familiar locations. Users have a one-hour window to react after a theft, during which biometric authentication is required to change settings. A workaround exists by disabling Significant Locations, but this limits the feature's usability. iOS 17.4 beta is expected to address these issues. The vulnerability affects all iPhone users who have upgraded to iOS 17.3. Apple has not yet released a patch for the flaw in the stable version.
Ask AI about this cluster
Answers cite the sources they use
Updated 104d ago How this analysis works
Timeline
2026-06-08
iOS 17.3 released
Apple launched iOS 17.3, introducing Stolen Device Protection among other features.
Article 22026-06-08
Flaw in Stolen Device Protection identified
A flaw was discovered that allows thieves to change settings if stolen in familiar locations.
Article 12026-06-08
Workaround suggested
Users are advised to disable Significant Locations to mitigate the flaw in Stolen Device Protection.
Article 1More articles in this cluster (2)
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…