Impact
This vulnerability involves improper state management in the Sign In With Apple authentication flow. An application could exploit this flaw to obtain authentication credentials and access a user's Apple Account without proper authorization. The weakness could allow an attacker to impersonate the user or gain unauthorized access to sensitive services tied to the Apple Account.
Affected Systems
Apple iOS and iPadOS running versions prior to 27; macOS versions prior to Golden Gate 27, Sequoia 15.8, or Tahoe 26.7; and visionOS versions prior to 27.
Risk and Exploitability
The CVE does not publish a CVSS score, and EPSS is unavailable. The vulnerability is not listed in the CISA KEV catalog, indicating no confirmed widespread exploitation at present. Nonetheless, because the flaw permits unauthorized access to user accounts via a widely used authentication mechanism, the potential impact for any affected device is significant. Attackers could abuse the Sign In With Apple flow to bypass expected state checks, a scenario that could be relatively straightforward once the flaw is known. The lack of known exploits does not diminish the risk that an attacker could develop a custom exploit targeting this state management issue.
OpenCVE Enrichment