I am currently facing the same issue.
I managed to debug using an affected device from a customer and I receive -25291 error when the app tries to add a new item to the keychain using "secItemAdd".
I tried restarting the device as Quinn mentioned, but I am still receiving the same error with the same expected result of the user unable to login.
Since this thread was posted over 2 years ago, I was wondering if you managed to find a solution to this? And did you file a bug as Quinn instructed?