CVE-2026-28895 describes a vulnerability in Apple iOS and iPadOS that could allow an attacker with physical access to a device, even with Stolen Device Protection enabled, to bypass biometric authentication and access Protected Apps using only the device passcode. This issue is rated Medium (CVSS 4.6) due to its requirement for physical access (AV:P) but carries a high confidentiality impact (C:H) by potentially exposing sensitive data within those applications. The vulnerability has been addressed in iOS 26.4 and iPadOS 26.4 with improved checks. There is currently no evidence of active exploitation, no public exploit code available, and it is not listed on CISA's Known Exploited Vulnerabilities catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 26.4CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | ||
< 26.4CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.