Impact
This issue was addressed with improved redaction of sensitive information, which can still allow an application to collect device‑specific identifiers or other metadata that may be used to fingerprint a user. The vulnerability aligns with CWE‑359, indicating that sensitive data was improperly exposed. No capability to execute code or disrupt services is mentioned, so the primary consequence remains the loss of user privacy rather than a direct attack on system integrity or availability.
Affected Systems
Affected product families are Apple iOS, iPadOS and macOS. The issue is fixed in iOS 18.7 and 26, iPadOS 18.7 and 26, macOS Sequoia 15.7, macOS Sonoma 14.8, and macOS Tahoe 26. Therefore, any build older than those specific versions is considered vulnerable.
Risk and Exploitability
The CVSS score of 5.5 signals moderate impact, while an EPSS score below 1 % indicates a very low probability of exploitation at this time. The vulnerability is not catalogued as a known exploited vulnerability by CISA. Based on the description, the attack vector appears to be local, requiring an installed application with access to improperly redacted logs or system data; there is no indication of remote exploitation capabilities or privilege escalation.
OpenCVE Enrichment
EUVD