Description
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. An app may be able to access sensitive user data.
Published: 2025-09-15
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Access
Action: Patch Now
AI Analysis

Impact

A permission misconfiguration allows a malicious or poorly designed application to read sensitive user data that it should not normally be able to access. The flaw falls under CWE‑284 (Incorrect Permission Management), implying that applications can exercise privileges beyond what was intended. The compromise enables an attacker to retrieve personal information, potentially violating confidentiality and privacy.

Affected Systems

The issue affects Apple devices running iOS, iPadOS, macOS (Tahoe), tvOS, visionOS, and watchOS. Devices running versions prior to the 26 release are potentially vulnerable; the vulnerability was resolved in the 26 update for each platform.

Risk and Exploitability

The CVSS score of 5.5 indicates a moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation would require a malicious application to be installed on the device, leveraging the elevated permissions to access protected data. The attack likely originates from the local device, but could be triggered remotely if the attacker can distribute a compromised app. At least one of the Apple-supported remediation paths involves installing the 26 updates, which eliminates the flaw.

Generated by OpenCVE AI on April 28, 2026 at 10:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest OS updates for iOS, iPadOS, macOS, tvOS, visionOS, and watchOS (version 26 or newer).
  • Remove or restrict any applications that request unnecessary access to sensitive data, especially those recently installed from unverified sources.
  • Enforce or review app permission settings to ensure the principle of least privilege is followed, limiting app access to the minimum required data.

Generated by OpenCVE AI on April 28, 2026 at 10:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-29328 A permissions issue was addressed with additional restrictions. This issue is fixed in tvOS 26, watchOS 26, visionOS 26, macOS Tahoe 26, iOS 26 and iPadOS 26. An app may be able to access sensitive user data.
History

Tue, 28 Apr 2026 11:15:00 +0000

Type Values Removed Values Added
Title Apple OS Permission Misconfiguration Enables Unauthorized Access to Sensitive User Data

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed with additional restrictions. This issue is fixed in visionOS 26, tvOS 26, iOS 26 and iPadOS 26, watchOS 26. An app may be able to access sensitive user data. A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. An app may be able to access sensitive user data.
References

Tue, 04 Nov 2025 02:30:00 +0000

Type Values Removed Values Added
References

Tue, 04 Nov 2025 01:45:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed with additional restrictions. This issue is fixed in tvOS 26, watchOS 26, visionOS 26, macOS Tahoe 26, iOS 26 and iPadOS 26. An app may be able to access sensitive user data. A permissions issue was addressed with additional restrictions. This issue is fixed in visionOS 26, tvOS 26, iOS 26 and iPadOS 26, watchOS 26. An app may be able to access sensitive user data.

Mon, 03 Nov 2025 19:30:00 +0000


Wed, 17 Sep 2025 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple iphone Os

Wed, 17 Sep 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios
Apple ipad Os
Apple ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios
Apple ipad Os
Apple ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Tue, 16 Sep 2025 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 15 Sep 2025 22:45:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed with additional restrictions. This issue is fixed in tvOS 26, watchOS 26, visionOS 26, macOS Tahoe 26, iOS 26 and iPadOS 26. An app may be able to access sensitive user data.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:12:57.612Z

Reserved: 2025-04-16T15:24:37.107Z

Link: CVE-2025-43317

cve-icon Vulnrichment

Updated: 2025-11-03T18:11:07.940Z

cve-icon NVD

Status : Modified

Published: 2025-09-15T23:15:34.730

Modified: 2026-04-02T19:20:25.100

Link: CVE-2025-43317

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T11:00:14Z

Weaknesses