Impact
A permission handling flaw, now addressed by stricter restrictions, allowed an application to gather identifying information about the user, effectively enabling a fingerprinting attack. The weakness aligns with confidentiality leakage (CWE-200). As described, the flaw could expose persistent device‑specific data without requiring elevated privileges.
Affected Systems
Apple devices running iPadOS and macOS are affected. The vulnerability is resolved in iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, and macOS Ventura 13.7.7. Any device using the mentioned operating systems prior to these releases is susceptible.
Risk and Exploitability
The CVSS score of 9.8 marks this flaw as critical, and the EPSS score of less than 1 % indicates a very low probability of observed exploitation at the time of analysis. The vulnerability is not yet catalogued in CISA's KEV list. The likely attack vector is a malicious or compromised application leveraging otherwise normal permissions to harvest user data on a local device. No public exploits are documented, but the high severity and broad affected scope warrant immediate remediation.
OpenCVE Enrichment
EUVD