Impact
A permissions flaw in Apple operating systems can allow a local application to read metadata of any file on the device. The weakness, classified as CWE-125, stems from insufficient restriction checks before granting file metadata access. Consequently, an attacker could exfiltrate file creation dates, owners, or other attributes that may help in profiling or in crafting follow‑up attacks, compromising confidentiality of system information.
Affected Systems
Apple devices running iOS 18.4 or earlier, iPadOS 18.4, iPadOS 17.7.7, macOS Sequoia 15.4, macOS Sonoma 14.7.5, tvOS 18.4, or watchOS 11.4 are impacted. The vulnerability applies across iPhone OS, iPadOS, macOS, tvOS, and watchOS variants and is mitigated by upgrading to the specified patched releases.
Risk and Exploitability
The CVSS score of 5 indicates a medium severity, and the EPSS score of less than 1% shows a very low probability of exploitation at the time of publication. The flaw does not appear in the CISA KEV catalog, suggesting no widely known weaponized exploits. Attackers would need to run or install an application with sufficient local privileges; the vector is most likely local rather than remote.
OpenCVE Enrichment
EUVD