Impact
This vulnerability arises because the operating system did not fully redact sensitive information, allowing an application to read protected user data. The exposure could lead to the unintended disclosure of confidential content.
Affected Systems
Apple iOS and iPadOS versions prior to 18.7.2 and macOS versions prior to Sequoia 15.7.2 or Tahoe 26.1 are affected; the problem was fixed in those newer releases.
Risk and Exploitability
The CVSS score of 7.5 indicates moderate to high severity, while the EPSS score of less than 1% suggests a low chance of exploitation. Attackers would likely need to install or compromise a local application that exploits the incomplete redaction logic to read protected data; the flaw does not appear to allow remote exploitation. The vulnerability is not listed in CISA's KEV catalog. The likely attack vector is through a malicious or compromised app, inferred from the description.
OpenCVE Enrichment