ID.me Authenticator
- Known vulnerabilities
- 0
- Still open
- 0
- KEV open
- 0
- Max CVSS (historical)
- —
Cumulative exposure
Low
Aggregates open CVEs (40%) + KEV (30%) + critical shared permissions (15%) + trackers (10%) + OS EOL (5%). Higher score = more exposed.
-
Open CVEs +0/+50
0 open CVEs, max CVSS 0.0, EPSS 0%
-
Active KEVs +0/+35
0 CISA KEVs still open
-
Permissions +0/+10
0 critical shared permission(s)
-
Trackers +0/+8
0 identification/profiling tracker(s)
-
EOL OS +0/+5
Installed OS is end-of-life
Based on permissions only: no CVE data referenced for this app.
Known vulnerabilities (CVE)
No CVE is currently referenced in NVD for this app on its platform.
The absence of CVEs is not a security guarantee — it can also mean nobody has audited or published findings.
Context
Context
Description
ID.me Authenticator is a simple and free multi-factor authentication (MFA) solution for your ID.me account, protecting your account from hackers by adding an additional layer of security. ID.me Authenticator generates secure 2-step verification tokens on your device, including time-based one-time passwords, (TOTP), push notifications, or mobile security keys, to verify your identity. When logging in, after entering in your password, you will be asked for an additional way to prove it is really you. Either approve the notification sent to the ID.me Authenticator by tapping ‘Yes’ to approve if it’s you (push notification), or enter the verification code generated by the app (TOTP).
Data collected and shared
Source: App Store · App Privacy · 2 data item(s) declared
Indicative classification based on data sensitivity. "Shared" = transmitted to third parties (publisher-declared).
FAQ
FAQ: ID.me Authenticator
Why are no CVEs listed for ID.me Authenticator?
No CVE is currently referenced in NVD for ID.me Authenticator (me.id.auth) with a iOS CPE configuration. Either none has been publicly disclosed, or none has been mapped yet. Absence of a CVE is not a security guarantee.
What is the latest known version of ID.me Authenticator?
The most recent version of ID.me Authenticator (me.id.auth) tracked by Appaloosa Scout is 1.5.17, published by ID.me, Inc..