Impact
Apple operating systems contain a flaw that allows applications to bypass the restrictions on protected data containers, giving them access to sensitive user data. The vulnerability is a data confidentiality weakness (CWE-200) and could lead to unauthorized read access to any resources stored within the device’s protected storage. The description indicates that any app capable of exploiting this weakness could read data that should be restricted to the operating system or the app owner.
Affected Systems
Affected Apple products include iOS and iPadOS on iPhone and iPad devices, and macOS Sequoia on Apple computers. The issue is fixed in iOS 18.4 and iPadOS 18.4, as well as in macOS Sequoia 15.4; all devices running earlier versions are vulnerable.
Risk and Exploitability
The CVSS score of 5.5 indicates medium severity, and the EPSS score of <1% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation would require an attacker to run a malicious or compromised application on the device, either through the App Store, sideloading, or enterprise deployment, to read protected user data. Based on the description, the attack vector is inferred to involve app installation; no evidence exists that the flaw can be abused remotely without app execution.
OpenCVE Enrichment
EUVD