Impact
This vulnerability involves improper flow. An application could exploit this flaw to obtain authentication credentials and access a user's Apple Account without proper authorization. The weakness could allow an attacker to impersonate the user or gain unauthorized access to sensitive services tied to the Apple Account.
Affected Systems
Apple iOS and iPadOS running versions earlier than 27; macOS versions earlier than Golden Gate 27, Sequoia 15.8, or Tahoe 26.7; and visionOS versions earlier than 27.
Risk and Exploitability
The EPSS score of less than 1% signals a very low likelihood of exploitation. A CVSS score of 7.1 indicates a high severity for authentication bypass. This vulnerability is not listed in the CISA KEV catalog, aligning with the low exploitation probability. While the flaw permits bypass of authentication checks during the Sign In With Apple flow, it could allow an attacker to gain unauthorized access to Apple accounts on affected devices. The risk remains limited by the low exploitation probability but remains significant if an attacker decides to target the specific state‑management flaw.
OpenCVE Enrichment