Impact
A permissions oversight in Apple operating systems allowed applications to read stored payment tokens, facilitating theft of confidential payment credentials. This flaw results from improper access control (CWE‑284). The CVSS score of 5.5 reflects a moderate severity; the vulnerability is not listed in CISA KEV, indicating no known widespread exploitation. The impact could compromise user financial data if the flaw is abused.
Affected Systems
Apple iOS, iPadOS, macOS, visionOS, and watchOS versions earlier than 26.2 are impacted. Devices running these older releases could permit an application to access sensitive payment tokens.
Risk and Exploitability
The EPSS score is reported as less than 1 %, indicating a low probability of exploitation. The flaw appears to require local app execution, with no remote attack vector described, so risk is confined to users who install or allow potentially malicious applications. Despite the low exploitation probability, the loss of sensitive payment data warrants swift remediation.
OpenCVE Enrichment