Description
Insufficient protection against brute-force and runtime manipulation in the local authentication component in Two App Studio Journey 5.5.6 on iOS allows local attackers to bypass biometric and PIN-based access control via repeated PIN attempts or dynamic code injection.
Problem types
CWE-287 Improper Authentication
Product status
Any version
Timeline
| 2025-03-12: | Vendor was contacted and informed about the vulnerability via email. |
| 2025-03-25: | Second attempt was made to contact vendor via email. |
| 2025-06-25: | Third attempt was made to contact vendor via email. |
Credits
Hannes Allmann (cirosec GmbH) <hannes.allmann@cirosec.de>
References
www.cirosec.de/sa/sa-2025-006