Impact
A privacy issue was addressed by moving sensitive data, allowing a malicious application to potentially fingerprint a user by leveraging the exposed identifiers. This results in unauthorized profiling, violating privacy and potentially enabling targeted attacks.
Affected Systems
Apple iOS and iPadOS systems running versions prior to 26.6 are affected; the fix is implemented in iOS 26.6 and iPadOS 26.6.
Risk and Exploitability
The vulnerability is not listed in CISA KEV and has an EPSS score of < 1%, indicating limited publicly known exploitation. The likely attack vector is an installed application that accesses the relocated sensitive data, inferred from the description. The CVSS score of 7.5 indicates a high‑impact vulnerability, but the low EPSS suggests that exploitation is unlikely at present, resulting in a moderate risk pending further disclosure.
OpenCVE Enrichment