Description
The issue was addressed with improved restriction of data container access. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An app may be able to access sensitive user data.
Published: 2025-03-31
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Data Exposure
Action: Update Software
AI Analysis

Impact

Apple operating systems contain a flaw that allows applications to bypass the restrictions on protected data containers, giving them access to sensitive user data. The vulnerability is a data confidentiality weakness (CWE-200) and could lead to unauthorized read access to any resources stored within the device’s protected storage. The description indicates that any app capable of exploiting this weakness could read data that should be restricted to the operating system or the app owner.

Affected Systems

Affected Apple products include iOS and iPadOS on iPhone and iPad devices, and macOS Sequoia on Apple computers. The issue is fixed in iOS 18.4 and iPadOS 18.4, as well as in macOS Sequoia 15.4; all devices running earlier versions are vulnerable.

Risk and Exploitability

The CVSS score of 5.5 indicates medium severity, and the EPSS score of <1% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation would require an attacker to run a malicious or compromised application on the device, either through the App Store, sideloading, or enterprise deployment, to read protected user data. Based on the description, the attack vector is inferred to involve app installation; no evidence exists that the flaw can be abused remotely without app execution.

Generated by OpenCVE AI on April 28, 2026 at 11:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest OS updates—iOS 18.4 or later, iPadOS 18.4 or later, and macOS Sequoia 15.4 or later—to remove the flaw.
  • If updates are unavailable, restrict the installation of third‑party applications and monitor apps that request broad data access permissions.
  • Verify that applications have only the minimal data permissions required for their functionality, and remediate or sandbox any that access sensitive containers without proper authorization.

Generated by OpenCVE AI on April 28, 2026 at 11:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-8900 The issue was addressed with improved restriction of data container access. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An app may be able to access sensitive user data.
History

Tue, 28 Apr 2026 12:15:00 +0000

Type Values Removed Values Added
Title Apple OS Vulnerability Allowing App Access to Sensitive Data Containers

Mon, 03 Nov 2025 22:30:00 +0000


Fri, 04 Apr 2025 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ipados
Apple iphone Os
Apple macos
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Vendors & Products Apple
Apple ipados
Apple iphone Os
Apple macos

Tue, 01 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 31 Mar 2025 22:45:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved restriction of data container access. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An app may be able to access sensitive user data.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:14:47.151Z

Reserved: 2025-03-22T00:04:43.722Z

Link: CVE-2025-30463

cve-icon Vulnrichment

Updated: 2025-11-03T21:16:00.779Z

cve-icon NVD

Status : Modified

Published: 2025-03-31T23:15:27.687

Modified: 2025-11-03T22:18:48.557

Link: CVE-2025-30463

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T12:00:13Z

Weaknesses