7.8
/ 10
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Description
Insufficient protection against brute-force and runtime manipulation in the local authentication component in Two App Studio Journey 5.5.6 on iOS allows local attackers to bypass biometric and PIN-based access control via repeated PIN attempts or dynamic code injection.
Basic Information
ID
CVE-2025-41459
Source
cirosec
Published
Jul 21, 2025 at 11:01
Modified
Jul 21, 2025 at 12:25
Affected Product
Vendor
Two App Studio
Product
Journey
Affected Versions
Two App Studio Journey 0