Impact
A missing permission check allows an application to read user‑sensitive data that it should not have access to. The weakness is an imprecise access control failure (CWE‑863) and could lead to privacy violations such as the disclosure of contacts, messages or system settings.
Affected Systems
Apple’s iOS, iPadOS, macOS, tvOS, visionOS and watchOS product lines are affected. The vulnerability is fixed in iOS 18.6, iPadOS 18.6 or 17.7.9, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6 and watchOS 11.6. Systems running earlier releases remain vulnerable.
Risk and Exploitability
The CVSS score of 4.0 indicates a low severity event, and the EPSS score of less than 1% suggests a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, and no public exploit has been documented. The attack surface is limited to local installations of the application; an attacker would need to persuade a user to run or install the vulnerable app. Nevertheless, the potential impact on confidential data justifies prompt remediation.
OpenCVE Enrichment
EUVD