CVE-2025-41459
7.8Two App Studio · Journey
A vulnerability in the Two App Studio Journey application allows local attackers to bypass biometric and PIN-based authentication through brute-force attempts or dynamic code injection.
Executive summary
A critical authentication bypass flaw in Two App Studio Journey permits local attackers to circumvent security controls, posing a significant risk to device and data integrity.
Vulnerability
The application fails to properly protect its local authentication component, allowing an attacker with local access to bypass biometric and PIN-based controls via repeated PIN guesses or dynamic code injection. This is an improper authentication issue (CWE-287) that requires local access to the device.
Business impact
Successful exploitation allows an unauthorized user to gain full access to the application, potentially exposing sensitive user data or performing unauthorized actions. Given the CVSS score of 7.8, this represents a high-severity risk, as it effectively renders the application's primary security boundary useless against a physical or local attacker.
Remediation
Immediate Action: Users should restrict physical access to the device and monitor for official updates from Two App Studio that address this authentication flaw.
Proactive Monitoring: Security teams should review device access logs for signs of repeated authentication failures or unusual application behavior indicative of brute-force attempts.
Compensating Controls: Ensure device-level encryption and remote wipe capabilities are enabled to minimize the impact of unauthorized physical access to the host device.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The ability to bypass PIN and biometric protections represents a severe failure in the application's security architecture. Organizations deploying this software should treat this vulnerability with high urgency and prioritize the application of vendor patches as soon as they become available to restore the integrity of the authentication mechanism.
More Two App Studio CVEs
Sources
Originally found and disclosed by Hannes Allmann (cirosec GmbH) <hannes.allmann@cirosec.de>, per the CVE Program record.