CVE-2026-28895 PUBLISHED CVSS 4.599999904632568 MEDIUM

The issue was addressed with improved checks. This issue is fixed in iOS 26.4 and iPadOS 26.4. An attacker with physical access to an iOS device with Stolen Device Protection enabled may be able to access biometrics-gated Protected Apps with the passcode.

EPSS 0.02% · 5.8th percentile

Risk Scores

CVSS v3.1
4.599999904632568
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.02%
5.8th percentile

Affected Products

VendorProductVersions
appleiphone_os0, 0
appleipados0, 0
AppleiOS and iPadOS0, 0

Timeline

References

Open in Interactive Console →