Impact
An Environment Variable handling vulnerability was discovered in Apple operating systems. The flaw allowed an application to read environment variables without adequate validation, potentially exposing sensitive user data. The issue is categorized as CWE‑20: Improper Input Validation.
Affected Systems
Apple iOS, iPadOS, macOS, visionOS, and watchOS are affected. Fixed releases include iOS 26.3, iPadOS 26.3, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3, and watchOS 26.3. Devices running earlier releases are vulnerable.
Risk and Exploitability
The CVSS score of 5.5 classifies this flaw as moderate severity, and the EPSS score of less than 1% indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the nature of environment variable access, the likely attack vector is local, where an application with sufficient privileges can read system or user environment variables. No remote exploitation path is documented in the provided information.
OpenCVE Enrichment