Impact
The vulnerability is a logic flaw in Apple iOS and iPadOS that allows an attacker to discover notes that the user has deleted. The flaw stems from inadequate state management, leading to residual data being accessible after deletion. This results in unintended information disclosure and is identified by CWE-200, which covers insufficient protection of information.
Affected Systems
Apple iOS and iPadOS devices are affected. The issue is present in the iOS 18.7.5, iOS 26.3, iPadOS 18.7.5 and iPadOS 26.3 operating systems. Applications running on these versions can potentially expose deleted note contents if a local attacker gains access to the device.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is below 1%, suggesting the exploitation probability is very low, and the vulnerability is not listed in CISA’s KEV catalogue. The attack vector for exploitation is not explicitly stated; however, based on the description it is inferred that an attacker would need local access to the device, possibly through physical possession or possession of the user’s pass‑code. Given the low EPSS and lack of recorded exploitation, the risk remains low but the potential for privacy breach warrants timely patching.
OpenCVE Enrichment