CVE-2025-41459

Publication date

2025-07-21 11:01:29

Family

cirosec

State

PUBLISHED

Description

Insufficient protection against brute-force and runtime manipulation in the local authentication component in Two App Studio Journey 5.5.6 on iOS allows local attackers to bypass biometric and PIN-based access control via repeated PIN attempts or dynamic code injection.