Impact
This vulnerability allows a malicious shortcut to read or access files that the Shortcuts app is normally restricted from reaching. The flaw is an improper access control weakness, identified as CWE‑284, and could enable an attacker to obtain sensitive data stored on the device. The impact is that an ordinarily sandboxed application could bypass its file‑system boundaries.
Affected Systems
Apple iOS, iPadOS, macOS, visionOS, and watchOS are affected. The security fix is available for iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, visionOS 2.4, and watchOS 11.4.
Risk and Exploitability
The CVSS score of 9.8 reflects a severe potential for damage if a malicious shortcut is executed. EPSS indicates a very low likelihood of exploitation (< 1 %). The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local, requiring a user to open a shortcut created by an attacker on the device; no remote network access is described.
OpenCVE Enrichment
EUVD