Description
A logic issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3. An attacker may be able to discover a user’s deleted notes.
Published: 2026-02-11
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure – Deleted Notes
Action: Patch
AI Analysis

Impact

The vulnerability is a logic flaw in Apple iOS and iPadOS that allows an attacker to discover notes that the user has deleted. The flaw stems from inadequate state management, leading to residual data being accessible after deletion. This results in unintended information disclosure and is identified by CWE-200, which covers insufficient protection of information.

Affected Systems

Apple iOS and iPadOS devices are affected. The issue is present in the iOS 18.7.5, iOS 26.3, iPadOS 18.7.5 and iPadOS 26.3 operating systems. Applications running on these versions can potentially expose deleted note contents if a local attacker gains access to the device.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. The EPSS score is below 1%, suggesting the exploitation probability is very low, and the vulnerability is not listed in CISA’s KEV catalogue. The attack vector for exploitation is not explicitly stated; however, based on the description it is inferred that an attacker would need local access to the device, possibly through physical possession or possession of the user’s pass‑code. Given the low EPSS and lack of recorded exploitation, the risk remains low but the potential for privacy breach warrants timely patching.

Generated by OpenCVE AI on April 15, 2026 at 21:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the device to the latest iOS or iPadOS version that contains the fix (iOS 18.7.5 or 26.3, iPadOS 18.7.5 or 26.3).
  • Remove or disable any third‑party mechanisms that may retain copies of notes beyond the operating system’s control.
  • Periodically review Apple security advisories to detect any new updates or related issues.

Generated by OpenCVE AI on April 15, 2026 at 21:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Apr 2026 21:30:00 +0000

Type Values Removed Values Added
Title Access to Deleted Notes via Logic Flaw

Wed, 25 Mar 2026 15:45:00 +0000

Type Values Removed Values Added
Description A logic issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, iOS 18.7.5 and iPadOS 18.7.5. An attacker may be able to discover a user’s deleted notes. A logic issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3. An attacker may be able to discover a user’s deleted notes.

Tue, 17 Feb 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 12 Feb 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Thu, 12 Feb 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Vendors & Products Apple
Apple ios And Ipados

Wed, 11 Feb 2026 23:15:00 +0000

Type Values Removed Values Added
Description A logic issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, iOS 18.7.5 and iPadOS 18.7.5. An attacker may be able to discover a user’s deleted notes.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:14:33.549Z

Reserved: 2025-11-11T14:43:07.873Z

Link: CVE-2026-20682

cve-icon Vulnrichment

Updated: 2026-02-17T15:29:09.355Z

cve-icon NVD

Status : Modified

Published: 2026-02-11T23:16:10.557

Modified: 2026-03-25T16:16:20.237

Link: CVE-2026-20682

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-15T21:15:13Z

Weaknesses