#VU121152 Protection mechanism failure in Apple iOS and iPadOS - CVE-2025-46286
Published: January 12, 2026
Apple iOS
iPadOS
Apple Inc.
Description
The vulnerability allows an attacker to bypass implemented security restrictions.
The vulnerability exists due to a logic issue in BiometricKit, which prevents passcode from being required immediately after Face ID enrollment when restoring system from a backup. An attacker with physical access to device can gain unauthorized access to the system.