Protection mechanism failure in Apple iOS and iPadOS - CVE-2025-46286
Published: January 12, 2026
Vulnerability details
The vulnerability allows an attacker to bypass implemented security restrictions.
The vulnerability exists due to a logic issue in BiometricKit, which prevents passcode from being required immediately after Face ID enrollment when restoring system from a backup. An attacker with physical access to device can gain unauthorized access to the system.
Affected software
iPadOS
How to mitigate CVE-2025-46286
iPadOS - update to 26.2 23C55