Impact
A logic issue in the mail preview functionality allowed remote content to load even when users disabled "Load remote content" in messages. This flaw could lead to unintended display of external images or scripts, potentially exposing user information or enabling phishing attempts. The issue is mitigated by additional checks introduced in the latest OS releases, which enforce the remote content restriction consistently.
Affected Systems
Apple iOS 18.7.5, iPadOS 18.7.5, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, and macOS Tahoe 26.3 are secure against this flaw. Earlier versions lacking the update are affected and may still exhibit the logic problem.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate risk. EPSS below 1% suggests low likelihood of exploitation at this time, and the vulnerability is not cataloged in the CISA KEV list. A likely attack would involve a malicious email posting remote content that bypasses the user's setting, potentially compromising confidentiality or delivering phishing payloads. This inference is based on the described behavior of the flaw.
OpenCVE Enrichment