Impact
An entitlement check was omitted in the Apple cloud folder sharing control, which allows an attacker to enable iCloud folder sharing without authenticating. This flaw is categorized as CWE-862 (Missing Authorization). The main consequence of the vulnerability is the potential exposure of a user’s personal data to unintended parties, compromising confidentiality and possibly leading to broader privacy violations.
Affected Systems
Apple devices running iOS 18.5, iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.4, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, and visionOS 2.5 are affected. The vulnerability applies across the iOS, iPadOS, macOS, and visionOS families.
Risk and Exploitability
The CVSS score of 9.1 places the flaw in the high‑severity range. The EPSS score is below 1%, indicating a very low probability of exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that an attacker may trigger the sharing action from the device or via iCloud, bypassing authentication checks and enabling unauthorized sharing of iCloud folders.
OpenCVE Enrichment
EUVD