Impact
The vulnerability arises from missing entitlement checks in the operating system, allowing an installed application to access user-sensitive information that should have been protected. The weakness is an Improper Access Control flaw (CWE‑284), resulting in a privacy breach without impacting device stability.
Affected Systems
Apple iOS and iPadOS devices running software versions prior to iOS 18.7.3, iPadOS 18.7.3, as well as earlier releases before iOS 26.2 and iPadOS 26.2 are affected. The issue applies across the entire iOS/iPadOS platform, regardless of device model.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, while an EPSS score of less than 1 % signals a very low chance of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the presence of an application that can request the specific entitlement, and the attacker would need that app installed on the target device. The attack vector is likely local via a malicious or compromised app, as the flaw involves entitlement checks within the operating system. Because the limitation to local application access reduces the likelihood of remote exploitation, the immediate risk is lower, but the privacy breach potential still necessitates timely patching.
OpenCVE Enrichment