Impact
An authorization flaw in Apple iOS and iPadOS allows an application to access sensitive user data that it should not see. The bug results from incorrect state handling, which the OS fixes in newer releases. This flaw enables disclosure of personally identifiable information, compromising user confidentiality.
Affected Systems
Apple iOS and iPadOS. All device operating system builds older than iOS 18.7.5, iPadOS 18.7.5, iOS 26.3, and iPadOS 26.3 are vulnerable.
Risk and Exploitability
The publicly reported CVSS score is 5.5, indicating a moderate security impact. The EPSS score of less than 1% suggests a very low probability of exploitation at this time, and the vulnerability is not listed in CISA’s KEV catalog. The nature of the issue points to a local attack model where a malicious or compromised application could gain unauthorized data access, typically requiring the user to install or run the app. Until an OS update is applied, the affected systems remain at moderate risk of data exposure.
OpenCVE Enrichment