Cybersecurity News Hub
No Result
View All Result
  • Home
  • Cyber Crime
  • Cyber Security
  • Data Breach
  • Mobile Security
  • Videos
  • Advertise
  • Privacy Policy
  • Contact Us
  • Home
  • Cyber Crime
  • Cyber Security
  • Data Breach
  • Mobile Security
  • Videos
  • Advertise
  • Privacy Policy
  • Contact Us
No Result
View All Result
Cybersecurity News Hub
No Result
View All Result
Home Mobile Security

Bypassing your apps’ biometric checks on iOS | by Wojciech Reguła | SecuRing

Cyberinchief by Cyberinchief
November 7, 2025
Reading Time: 5 mins read
0
Bypassing your apps’ biometric checks on iOS | by Wojciech Reguła | SecuRing


Wojciech Reguła

Press enter or click to view image in full size

Using iOS biometrics features like Touch ID and Face ID is a really convenient way to authenticate a user before performing sensitive actions. These actions, of course, depend on apps’ features. Usually, we test apps that use TouchID/FaceID to log in and to confirm financial actions (e.g. wire transfer). But, do these checks can be treated as 100% secure?

The answer is of course not. Biometrics checks are performed on your device, and like any others ‘client-side checks’ can be bypassed if attacker can control the application/device. In this blog post, I want to show you how easy that hack may be done. To perform the attack, we need:

  • jailbroken device (if you do not have one, check this presentation),
  • Frida,
  • text editor. 😉

Sample app — SecuBank

I prepared a really simple application that asks you for your finger/face and displays a message if the verification was successful or not.

Note that the application’s logic was implemented in Swift:

Frida script

Now, we have to write a Frida script that bypasses the check. As you can see in the above-pasted code snippet, the evaluatePolicy uses a callback that determines the result. So, the easiest way to achieve the hack is to intercept that callback and make sure it always returns the success=1.

Hacking the SecuBank

At this moment, we just need to open the SecuBank and load the script with Frida:

RELATED POSTS

Top 5 Mobile App Security Threats Leaders Must Prepare for in 2026

Emerging Technology Management for Modern IT Leaders

Adopting Blueprints in Jamf Tools

$frida -U -l bypass.js -f biz.securing.SecuBank --no-pause

Summary

In this article, I showed you again that any kind of local checks can be bypassed, including the biometrics ones provided by the iOS/macOS. These checks are really convenient, but you have always to remember that they cannot guarantee any reliability if the device is jailbroken.

If you are interested in implementing such jailbreak checks, take a look at the iOS Security Suite — our open source project!



Source link

Buy JNews
ADVERTISEMENT
Tags: AppsbiometricBypassingchecksiOSRegułaSecuringWojciech
ShareTweetPin
Cyberinchief

Cyberinchief

Related Posts

Top 5 Mobile App Security Threats Leaders Must Prepare for in 2026
Mobile Security

Top 5 Mobile App Security Threats Leaders Must Prepare for in 2026

January 21, 2026
Emerging Technology Management for Modern IT Leaders
Mobile Security

Emerging Technology Management for Modern IT Leaders

December 8, 2025
Adopting Blueprints in Jamf Tools
Mobile Security

Adopting Blueprints in Jamf Tools

December 8, 2025
Jamf Safe Internet + On-Device Phishing AI
Mobile Security

Jamf Safe Internet + On-Device Phishing AI

December 7, 2025
Act on Jamf Protect Alerts
Mobile Security

Act on Jamf Protect Alerts

December 7, 2025
Terraform + GitLab CI/CD for Jamf
Mobile Security

Terraform + GitLab CI/CD for Jamf

December 6, 2025
Next Post
Cyber crime ke dwara bank account se lien amount deduct Kiya gaya ab kya Kare? #shorts #bank #lien

Cyber crime ke dwara bank account se lien amount deduct Kiya gaya ab kya Kare? #shorts #bank #lien

Defending digital identity from computer-using agents (CUAs)

Defending digital identity from computer-using agents (CUAs)

Recommended Stories

🔥Salary of Cyber Security Engineer | How Much does a Cyber Security Engineer Make #Simplilearn

🔥Salary of Cyber Security Engineer | How Much does a Cyber Security Engineer Make #Simplilearn

October 14, 2025
police#cyber crime#crimenews #latest #odisha #news #puri #sangharsatv

police#cyber crime#crimenews #latest #odisha #news #puri #sangharsatv

October 25, 2025
YUK MENGENAL APA ITU KEAMANAN SIBER – CYBER SECURITY

YUK MENGENAL APA ITU KEAMANAN SIBER – CYBER SECURITY

November 6, 2025

Popular Stories

  • Allianz Life – 1,115,061 breached accounts

    Allianz Life – 1,115,061 breached accounts

    0 shares
    Share 0 Tweet 0
  • Prosper – 17,605,276 breached accounts

    0 shares
    Share 0 Tweet 0
  • साइबर अपराध | Illegal Payment Gateway & Rented Bank Accounts | MAMTA CHOPRA

    0 shares
    Share 0 Tweet 0
  • Miljödata – 870,108 breached accounts

    0 shares
    Share 0 Tweet 0
  • Snowflake Data Breach Explained: Lessons and Protection Strategies

    0 shares
    Share 0 Tweet 0

Search

No Result
View All Result

Recent Posts

  • Top 5 Mobile App Security Threats Leaders Must Prepare for in 2026
  • Microsoft On Women In Cybersecurity At Black Hat Europe 2025 In London
  • Polisi kembali ungkap sindikat Cyber Crime kejahatan Internasional – iNews Malam 09/03

Categories

  • Cyber Crime
  • Cyber Security
  • Data Breach
  • Mobile Security
  • Videos

Newsletter

© 2025 All rights reserved by cyberinchief.com

No Result
View All Result
  • Home
  • Cyber Crime
  • Cyber Security
  • Data Breach
  • Mobile Security
  • Videos
  • Advertise
  • Privacy Policy
  • Contact Us

© 2025 All rights reserved by cyberinchief.com

Newsletter Signup

Subscribe to our weekly newsletter below and never miss the latest News.

Enter your email address

Thanks, I’m not interested