Impact
This vulnerability allows a remote controller to unintentionally reveal password fields during a FaceTime session. The weakness is an information exposure flaw (CWE-200), enabling an attacker to harvest credentials by watching the remote user’s screen while they are entering sensitive data.
Affected Systems
Apple iOS 18.7.3, iPadOS 18.7.3, iOS 26.2, iPadOS 26.2, macOS Sequoia 15.7.3, macOS Tahoe 26.2, visionOS 26.2 are affected; any device running these operating systems could leak passwords when remotely controlled over FaceTime.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity for information disclosure. The EPSS score is below 1%, suggesting a very low likelihood of public exploitation at present, and the vulnerability is not listed in CISA KEV. The attack vector is inferred to be an authorized remote connection via FaceTime; the attacker mounts a remote session and watches the compromised device’s screen to capture passwords that are input but not masked properly.
OpenCVE Enrichment