Impact
An improper access control flaw in the handling of environment variables allows an application to read data that should be restricted. Because the flaw exposes sensitive system information, it can lead to information disclosure. The weakness is captured by CWE-284, Improper Access Control.
Affected Systems
The flaw affects Apple operating systems. Devices running iOS or iPadOS earlier than version 26.1, macOS Tahoe earlier than 26, tvOS earlier than 26.1, and watchOS earlier than 26.1 are vulnerable. The fix has been delivered in those OS releases.
Risk and Exploitability
The CVSS score is 3.3, reflecting a low severity due to the limited scope of the vulnerability. The EPSS score is below 1%, indicating that exploitation is unlikely. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to install a malicious or compromised application on the device to read environment variables, so the attack vector is local and limited to the affected OS environments.
OpenCVE Enrichment
EUVD