Impact
The vulnerability allows an attacker who has physical access to a locked Apple device to bypass existing security checks and view sensitive user data, leading to information disclosure. This weakness is classified as a confidentiality breach (CWE-200) because it enables unauthorized insight into data that should remain private.
Affected Systems
The flaw affects Apple operating systems across the iPhone, iPad, Mac, vision, and watch platforms. Unpatched versions of iOS, iPadOS, macOS Sequoia, visionOS, and watchOS are vulnerable until the security updates described below are installed. The official Apple fix is available in iOS 18.4, iPad 18.4, macOS 15.4, visionOS 2.4, and watchOS 11.4.
Risk and Exploitability
The CVSS score of 4.6 indicates moderate severity; the EPSS score of less than 1 % signals low expected exploitation likelihood. Because the attack requires physical access to a locked device, the threat is limited to scenarios where an adversary can physically obtain or tamper with the device. The vulnerability is not listed in the CISA KEV catalog, but the potential for data exposure remains significant for affected users.
OpenCVE Enrichment
EUVD