Security Advisory

CVE-2025-41459

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-07-21 11:01:29
Last updated 2025-08-27 06:34:27
Assigner cirosec
CVSS score 7.8
State PUBLISHED

Description

Insufficient protection against brute-force and runtime manipulation in the local authentication component in Two App Studio Journey 5.5.6 on iOS allows local attackers to bypass biometric and PIN-based access control via repeated PIN attempts or dynamic code injection.