Impact
A logic flaw in Apple iOS and iPadOS allows the VoiceOver accessibility feature to read aloud the device passcode during entry, potentially exposing the credential to anyone able to hear the device. This flaw lets an attacker obtain the passcode without bypassing the authentication process. The weakness aligns with improper handling of authentication credentials (CWE‑261) and directly threatens user confidentiality.
Affected Systems
The vulnerability affects Apple iOS and iPadOS devices running versions prior to iOS 18.6 and iPadOS 18.6. All affected models are susceptible until the official update is applied.
Risk and Exploitability
The flaw carries a CVSS score of 9.1, indicating critical severity, while the EPSS score of less than 1% suggests low likelihood of widespread exploitation at present. It is not listed in the CISA KEV catalog. Likely attack vectors involve a local attacker who can force the device into a state where VoiceOver is active while the passcode is entered, then capture the spoken passcode. No remote exploitation is documented in the description.
OpenCVE Enrichment
EUVD