The issue was addressed with improved checks. This issue is fixed in iOS 26.4 and iPadOS 26.4. An attacker with physical access to an iOS device with Stolen Device Protection enabled may be able to access biometrics-gated Protected Apps with the passcode.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://support.apple.com/en-us/126792 |
|
History
Wed, 25 Mar 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Local Attack Enables Unauthorized Access to Biometric‑Gated Protected Apps | |
| Weaknesses | CWE-287 |
Wed, 25 Mar 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 | |
| Metrics |
cvssV3_1
|
Wed, 25 Mar 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apple
Apple ios And Ipados |
|
| Vendors & Products |
Apple
Apple ios And Ipados |
Wed, 25 Mar 2026 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The issue was addressed with improved checks. This issue is fixed in iOS 26.4 and iPadOS 26.4. An attacker with physical access to an iOS device with Stolen Device Protection enabled may be able to access biometrics-gated Protected Apps with the passcode. | |
| References |
|
Status: PUBLISHED
Assigner: apple
Published:
Updated: 2026-03-25T20:21:06.907Z
Reserved: 2026-03-03T16:36:03.981Z
Link: CVE-2026-28895
Updated: 2026-03-25T20:21:03.352Z
Status : Undergoing Analysis
Published: 2026-03-25T01:17:12.973
Modified: 2026-03-25T21:16:40.713
Link: CVE-2026-28895
No data.
OpenCVE Enrichment
Updated: 2026-03-25T20:56:17Z