Impact
An improper state management flaw allows an application to read sensitive user data. The vulnerability falls under the Access Control weakness identified by CWE-284. The data exposed could include personal information, authentication tokens, or other confidential content stored on the device; disclosure would compromise user privacy and confidentiality.
Affected Systems
Apple iOS, iPadOS, macOS, tvOS, visionOS, and watchOS are affected. The flaw is addressed in iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, and watchOS 11.5. Devices running earlier releases are susceptible.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate severity. The EPSS score of less than 1% suggests a very low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Exploitation would likely require an attacker to install or run a malicious or compromised application on the device, allowing that app to read protected data.
OpenCVE Enrichment
EUVD