Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-58pv-hg46-37r9

Опубликовано: 20 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 4.3
CVSS3: 4.8

Описание

capacitor-native-biometric before 12.128.2 contains an authentication bypass vulnerability where the onAuthenticationSucceeded() method fails to validate CryptoObject parameters. Attackers can hook the onAuthenticationSucceeded() function using dynamic instrumentation to bypass biometric authentication without valid credentials.

capacitor-native-biometric before 12.128.2 contains an authentication bypass vulnerability where the onAuthenticationSucceeded() method fails to validate CryptoObject parameters. Attackers can hook the onAuthenticationSucceeded() function using dynamic instrumentation to bypass biometric authentication without valid credentials.

EPSS

Процентиль: 12%
0.00217
Низкий

4.3 Medium

CVSS4

4.8 Medium

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 4.8
nvd
3 месяца назад

capacitor-native-biometric before 12.128.2 contains an authentication bypass vulnerability where the onAuthenticationSucceeded() method fails to validate CryptoObject parameters. Attackers can hook the onAuthenticationSucceeded() function using dynamic instrumentation to bypass biometric authentication without valid credentials.

EPSS

Процентиль: 12%
0.00217
Низкий

4.3 Medium

CVSS4

4.8 Medium

CVSS3

Дефекты

CWE-287