Impact
A permission misconfiguration allows a malicious or poorly designed application to read sensitive user data that it should not normally be able to access. The flaw falls under CWE‑284 (Incorrect Permission Management), implying that applications can exercise privileges beyond what was intended. The compromise enables an attacker to retrieve personal information, potentially violating confidentiality and privacy.
Affected Systems
The issue affects Apple devices running iOS, iPadOS, macOS (Tahoe), tvOS, visionOS, and watchOS. Devices running versions prior to the 26 release are potentially vulnerable; the vulnerability was resolved in the 26 update for each platform.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation would require a malicious application to be installed on the device, leveraging the elevated permissions to access protected data. The attack likely originates from the local device, but could be triggered remotely if the attacker can distribute a compromised app. At least one of the Apple-supported remediation paths involves installing the 26 updates, which eliminates the flaw.
OpenCVE Enrichment
EUVD