Impact
A flaw in state management allows an application to read sensitive user data that it should not access. The vulnerability is related to improper handling of application state, resulting in information exposure. Though the CVSS score of 5.5 indicates moderate severity, the risk is mitigated by the low EPSS score of less than 1% and absence from CISA’s KEV catalog.
Affected Systems
Apple devices running iOS or iPadOS versions before 18.4, macOS Sequoia before 15.4, macOS Sonoma before 14.7.5, macOS Ventura before 13.7.5, tvOS before 18.4, and watchOS before 11.4 are vulnerable. The affected products include Apple iOS, iPadOS, macOS (Sequoia, Sonoma, Ventura), tvOS, and watchOS.
Risk and Exploitability
The vulnerability is exploitable within the local application context; an attacker who installs or controls a malicious app could access private data through the state mismanagement flaw. Given the current EPSS <1% and moderate CVSS score, the likelihood of widespread exploitation is low, but organizations should address it promptly. No known public exploit has been reported and it is not listed in the KEV catalog.
OpenCVE Enrichment
EUVD