Impact
This vulnerability allows an attacker who has physical access to a locked Apple device to view sensitive user information. The flaw occurs because the lock screen still presents options that expose data, representing an improper access control weakness (CWE‑284). The impact is limited to information disclosure, with no remote execution or denial‑of‑service effect described.
Affected Systems
Apple iOS and iPadOS devices are affected. The issue persists in any operating system release before iOS 18.7.2, iPadOS 18.7.2, iOS 26.1 or iPadOS 26.1. Versions released after these updates contain the fix.
Risk and Exploitability
The CVSS score of 4.6 indicates moderate severity, and the EPSS score of less than 1 % shows a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attackers must physically access the locked device and the affected option must be visible on the lock screen, confining the risk to environments where the device is left unattended or where an attacker can gain nearby access.
OpenCVE Enrichment