DID Wallet Automatically Enables TouchID Without Password
- Description The DID Wallet app enables TouchID for authentication without requiring the user to first enter their password. This bypasses the standard security flow, creating a risk of unauthorized access if the device is stolen or shared.
- Steps to Reproduce Open the DID Wallet app. Attempt to access a secured feature Instead of being prompted for a password, the app automatically enables TouchID for authentication. Observe that no password input is required to proceed.
- Expected Behavior Users should first enter their password to unlock the wallet. TouchID should only be enabled after successful password authentication (as a convenience option).
- Actual Behavior TouchID is enabled without password verification, allowing access to sensitive data or transactions.
- Severity Priority: Critical (Security/Authentication Bypass)