Impact
An Apple OS vulnerability permits an application to read sensitive user data that it should not have access to. The flaw was caused by insufficient validation within system components, which allowed apps to access protected information. This can compromise the confidentiality of personal data, leading to privacy violations or further exploitation if the data is used maliciously.
Affected Systems
Vulnerable platforms include Apple iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. The issue is resolved in version 26.4 for each operating system, but earlier releases remain at risk because the affected versions are not specified in the advisory.
Risk and Exploitability
The vulnerability receives a moderate CVSS score of 5.5 and an EPSS score of less than 1%, suggesting low overall exploitation likelihood. It is not listed in CISA's Known Exploited Vulnerabilities catalog. The attack vector appears to be application‑based, meaning a malicious or poorly designed app could trigger the information leak. Theoretical remote exploitation does not seem plausible based on the description provided.
OpenCVE Enrichment