CVE-2025-41459: Two App Studio Journey
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
Insufficient protection against brute-force and runtime manipulation in the local authentication component in Two App Studio Journey 5.5.6 on iOS allows local attackers to bypass biometric and PIN-based access control via repeated PIN attempts or dynamic code injection.
Affected products
- Two App Studio Journey: up to and including 5.5.9
Published 2025-07-21. Last modified 2026-06-17.