passforios icon indicating copy to clipboard operation
passforios copied to clipboard

Pass ignores Face/Touch ID authentication when autofilling passwords

Open rnkn opened this issue 3 years ago • 0 comments

As hinted by #537 when the user has AutoFill enabled for Pass, in Safari or any app requesting to autofill a password, the authentication of Face/Touch ID is ignored and passwords are filled regardless. The user may simply tap cancel on the authentication prompt.

An attacker with access to an unlocked iPhone effectively has access to any password-protected website.

rnkn avatar Jul 14 '22 08:07 rnkn