Executive brief
The capacitor-native-biometric library, used by mobile applications to implement fingerprint and facial recognition login, contains a security flaw that allows biometric authentication to be bypassed. By using specialized software tools on a device they physically possess, an attacker can trick the application into believing a successful biometric scan occurred without providing valid credentials. This could lead to unauthorized access to sensitive user data or restricted app features.
Technical details
An authentication bypass vulnerability exists in the capacitor-native-biometric library (specifically in AuthActivity.java) due to improper validation of the CryptoObject within the onAuthenticationSucceeded() callback. The implementation only verifies that the callback was triggered rather than ensuring the integrity of the cryptographic result. An attacker with physical access to a device can use dynamic instrumentation tools like Frida to hook the onAuthenticationSucceeded() function and inject a null or spoofed CryptoObject, effectively bypassing biometric requirements. This issue is resolved in version 12.128.2.
Affected products
- Cap-go capacitor-native-biometric < 12.128.2
Timeline
- 2026-02-10: advisory: Initial GitHub security advisory published
- 2026-06-20: disclosed: NVD publication date