CVE-2026-56294

capacitor-native-biometric before 12.128.2 contains an authentication bypass vulnerability where the onAuthenticationSucceeded() method fails to validate CryptoObject parameters. Attackers can hook the onAuthenticationSucceeded() function using dynamic instrumentation to bypass biometric authentication without valid credentials.
Configurations

No configuration.

History

No history.

Information

Published : 2026-06-20 16:17

Updated : 2026-06-22 21:14


NVD link : CVE-2026-56294

Mitre link : CVE-2026-56294

CVE.ORG link : CVE-2026-56294


JSON object : View

Products Affected

No product.

CWE
CWE-287

Improper Authentication