Impact
A permissions issue allows an application to escape its sandbox. This weakness is categorized as an access control violation (CWE‑284). The impact is that a malicious or compromised app could access or modify resources outside its intended confinement, potentially exposing sensitive data or executing unauthorized code.
Affected Systems
Apple iOS, iPadOS, macOS, tvOS, visionOS, and watchOS are affected. The vulnerability is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, and watchOS 26.3.
Risk and Exploitability
The CVSS score is 7.1, indicating a moderate‑to‑high severity. EPSS is under 1 %, indicating a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Likely exploitation requires local execution of a malicious or compromised app; therefore the primary attack vector is a local user or an app that can be sideloaded onto the device.
OpenCVE Enrichment