CVE-2026-56294

MEDIUM

capacitor-native-biometric - Authentication Bypass via Unvalidated CryptoObject in onAuthenticationSucceeded

Title source: cna
STIX 2.1

Description

capacitor-native-biometric before 12.128.2 contains an authentication bypass vulnerability where the onAuthenticationSucceeded() method fails to validate CryptoObject parameters. Attackers can hook the onAuthenticationSucceeded() function using dynamic instrumentation to bypass biometric authentication without valid credentials.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
GHSA Advisory GHSA-vx5f-vmr6-32wf
https://github.com/Cap-go/capgo/security/advisories/GHSA-vx5f-vmr6-32wf
Third Party Advisory third-party-advisory
VulnCheck Advisory: capacitor-native-biometric - Authentication Bypass via Unvalidated CryptoObject in onAuthenticationSucceeded
https://www.vulncheck.com/advisories/capacitor-native-biometric-authentication-bypass-via-unvalidated-cryptoobject-in-onauthenticationsucceeded

Scores

CVSS v3 4.8
EPSS 0.0022
EPSS Percentile 12.3%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-287
Status published
Products (2)
capacitor-native-biometric/capacitor-native-biometric < 12.128.2
capacitor-native-biometric/capacitor-native-biometric 12.128.2
Published Jun 20, 2026
Tracked Since Jun 20, 2026