PT-2026-27611 · Apple · Ipados+3
Published
2026-03-24
·
Updated
2026-04-18
·
CVE-2026-28895
CVSS v3.1
4.6
Medium
| Vector | AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
iOS versions prior to 26.4
iPadOS versions prior to 26.4
Description
A security issue exists where an attacker with physical access to an iOS device with Stolen Device Protection enabled may be able to access biometrics-gated Protected Apps with the passcode. The issue was addressed with improved checks. The affected components include Spotlight and UIKit.
Recommendations
Update to iOS version 26.4.
Update to iPadOS version 26.4.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Spotlight
Uikit
Ios
Ipados