Description
This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2. An app may be able to access user-sensitive data.
Published: 2025-12-17
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access to Sensitive Data
Action: Apply Fix
AI Analysis

Impact

The vulnerability arises from missing entitlement checks in the operating system, allowing an installed application to access user-sensitive information that should have been protected. The weakness is an Improper Access Control flaw (CWE‑284), resulting in a privacy breach without impacting device stability.

Affected Systems

Apple iOS and iPadOS devices running software versions prior to iOS 18.7.3, iPadOS 18.7.3, as well as earlier releases before iOS 26.2 and iPadOS 26.2 are affected. The issue applies across the entire iOS/iPadOS platform, regardless of device model.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate severity, while an EPSS score of less than 1 % signals a very low chance of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the presence of an application that can request the specific entitlement, and the attacker would need that app installed on the target device. The attack vector is likely local via a malicious or compromised app, as the flaw involves entitlement checks within the operating system. Because the limitation to local application access reduces the likelihood of remote exploitation, the immediate risk is lower, but the privacy breach potential still necessitates timely patching.

Generated by OpenCVE AI on April 22, 2026 at 20:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the device to Apple iOS 18.7.3 or later, or iPadOS 18.7.3 or later, or iOS 26.2 / iPadOS 26.2, which include the entitlement check fix.
  • Reboot the device after the update to ensure all entitlement changes take effect.
  • Regularly review installed applications and remove those that are unnecessary or from untrusted developers to reduce the attack surface.

Generated by OpenCVE AI on April 22, 2026 at 20:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 22 Apr 2026 20:45:00 +0000

Type Values Removed Values Added
Title iOS/iPadOS Entitlement Check Bypass Leading to Data Exposure

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Description This issue was addressed with additional entitlement checks. This issue is fixed in iOS 26.2 and iPadOS 26.2, iOS 18.7.3 and iPadOS 18.7.3. An app may be able to access user-sensitive data. This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2. An app may be able to access user-sensitive data.

Thu, 18 Dec 2025 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}


Thu, 18 Dec 2025 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple iphone Os
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
Vendors & Products Apple iphone Os
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Thu, 18 Dec 2025 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios
Apple ipados
Vendors & Products Apple
Apple ios
Apple ipados

Wed, 17 Dec 2025 21:00:00 +0000

Type Values Removed Values Added
Description This issue was addressed with additional entitlement checks. This issue is fixed in iOS 26.2 and iPadOS 26.2, iOS 18.7.3 and iPadOS 18.7.3. An app may be able to access user-sensitive data.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:12:40.756Z

Reserved: 2025-04-22T21:13:49.959Z

Link: CVE-2025-46292

cve-icon Vulnrichment

Updated: 2025-12-18T19:14:39.344Z

cve-icon NVD

Status : Modified

Published: 2025-12-17T21:16:14.377

Modified: 2026-04-02T19:21:04.673

Link: CVE-2025-46292

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-22T20:30:26Z

Weaknesses