CVE-2025-41459: Two App Studio Journey

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

Insufficient protection against brute-force and runtime manipulation in the local authentication component in Two App Studio Journey 5.5.6 on iOS allows local attackers to bypass biometric and PIN-based access control via repeated PIN attempts or dynamic code injection.

Affected products

Published 2025-07-21. Last modified 2026-06-17.