Impact
A logic flaw in Apple iOS and iPadOS allows an attacker who has physical possession of a device to recover a deleted call recording. The flaw is due to insufficient checks when handling deleted media, enabling the deleted data to remain accessible. This results in a confidentiality breach where private communications could be exposed to an unauthorized party.
Affected Systems
Apple iOS and iPadOS devices running versions earlier than iOS 18.5 or iPadOS 18.5 are affected. The vulnerability is present in all earlier releases of these operating systems.
Risk and Exploitability
The CVSS score of 4.6 indicates a moderate risk level, but the EPSS score of less than 1% suggests that the probability of exploitation is very low at present. The vulnerability is not listed in the CISA KEV catalog, and the attack vector requires physical access to the device. Because of the low external exposure, the overall risk to the broader ecosystem is limited, though any device that is not locked or otherwise protected from physical access remains vulnerable.
OpenCVE Enrichment
EUVD