| Summary | A vulnerability in Okta Verify for iOS versions 9.25.1 (beta) and 9.27.0 (including beta) allows push notification responses through the iOS ContextExtension feature allowing the authentication to proceed regardless of the user’s selection. When a user long-presses the notification banner and selects an option, both options allow the authentication to succeed. A pre-condition for this vulnerability is that the user must have enrolled in Okta Verify while the Okta customer was using Okta Classic. This applies irrespective of whether the organization has since upgraded to Okta Identity Engine. |
|---|---|
| Publication Date | Oct. 25, 2024, 6:15 a.m. |
| Registration Date | Oct. 25, 2024, noon |
| Last Update | Oct. 25, 2024, 9:56 p.m. |