The issue was addressed with improved checks. This issue is fixed in iOS 26.4 and iPadOS 26.4. An attacker with physical access to an iOS device with Stolen Device Protection enabled may be able to access biometrics-gated Protected Apps with the passcode.
Metrics
Affected Vendors & Products
References
History
Thu, 26 Mar 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apple ipados
Apple iphone Os |
|
| CPEs | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Apple ipados
Apple iphone Os |
Thu, 26 Mar 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Local Attack Enables Unauthorized Access to Biometric‑Gated Protected Apps | |
| Weaknesses | CWE-287 |
Wed, 25 Mar 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Local Attack Enables Unauthorized Access to Biometric‑Gated Protected Apps | |
| Weaknesses | CWE-287 |
Wed, 25 Mar 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 | |
| Metrics |
cvssV3_1
|
Wed, 25 Mar 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apple
Apple ios And Ipados |
|
| Vendors & Products |
Apple
Apple ios And Ipados |
Wed, 25 Mar 2026 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The issue was addressed with improved checks. This issue is fixed in iOS 26.4 and iPadOS 26.4. An attacker with physical access to an iOS device with Stolen Device Protection enabled may be able to access biometrics-gated Protected Apps with the passcode. | |
| References |
|
Status: PUBLISHED
Assigner: apple
Published:
Updated: 2026-03-25T20:21:06.907Z
Reserved: 2026-03-03T16:36:03.981Z
Link: CVE-2026-28895
Updated: 2026-03-25T20:21:03.352Z
Status : Analyzed
Published: 2026-03-25T01:17:12.973
Modified: 2026-03-26T18:58:05.020
Link: CVE-2026-28895
No data.