Vulnerability Details CVE-2025-46286
A logic issue was addressed with improved validation. This issue is fixed in iOS 26.2 and iPadOS 26.2. Restoring from a backup may prevent passcode from being required immediately after Face ID enrollment.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 6.5%
CVSS Severity
CVSS v3 Score 4.3
Products affected by CVE-2025-46286
-
cpe:2.3:o:apple:ipados:15.8.7
-
cpe:2.3:o:apple:ipados:16.7.15
-
cpe:2.3:o:apple:ipados:18.7.5
-
cpe:2.3:o:apple:ipados:18.7.7
-
cpe:2.3:o:apple:ipados:18.7.8
-
cpe:2.3:o:apple:ipados:18.7.9
-
cpe:2.3:o:apple:iphone_os:15.8.7
-
cpe:2.3:o:apple:iphone_os:16.7.15
-
cpe:2.3:o:apple:iphone_os:18.7.5
-
cpe:2.3:o:apple:iphone_os:18.7.7
-
cpe:2.3:o:apple:iphone_os:18.7.8
-
cpe:2.3:o:apple:iphone_os:18.7.9