CVE Vulnerabilities

CVE-2025-46286

Authentication Bypass Using an Alternate Path or Channel

Published: Jan 09, 2026 | Modified: Jan 14, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A logic issue was addressed with improved validation. This issue is fixed in iOS 26.2 and iPadOS 26.2. Restoring from a backup may prevent passcode from being required immediately after Face ID enrollment.

Weakness

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Affected Software

NameVendorStart VersionEnd Version
IpadosApple*26.2 (excluding)
Iphone_osApple*26.2 (excluding)

Potential Mitigations

References