CVE-2025-41459 Information

Description

Insufficient protection against brute-force and runtime manipulation in the local authentication component in Two App Studio Journey 5.5.6 on iOS allows local attackers to bypass biometric and PIN-based access control via repeated PIN attempts or dynamic code injection.

Reference

https://www.cirosec.de/sa/sa-2025-006

CNNVD-202507-2631 (Published: 2025-07-21)

Share on: