Impact
An attacker who can physically reach the device may override the network settings that are normally locked by managed Wi‑Fi profiles. The flaw is classified as a weak access control issue (CWE‑284) and is scored modestly with a CVSS of 2.4, indicating limited impact compared to higher‑score vulnerabilities.
Affected Systems
Apple iOS and iPadOS devices are affected. The vulnerability was corrected in iOS 18.5 and iPadOS 18.5, as well as iPadOS 17.7.7; older releases, including all previous iOS and iPadOS versions, remain vulnerable unless patched.
Risk and Exploitability
The EPSS score is below 1 %, the KEV list does not include this CVE, and the attack surface requires physical possession of the device. Overall this is a low‑risk issue that is unlikely to be targeted in the wild but could be exploited in a controlled environment by an insider or thief with direct device access.
OpenCVE Enrichment