Impact
An inconsistent user interface state management flaw allows a malicious app to potentially read sensitive user data that it should not access, leading to disclosure of private information. The flaw involves improper handling of application state, which can expose data when an app transitions between contexts. The impact is restricted to the confidentiality of user data rather than system integrity or availability.
Affected Systems
Apple iOS, iPadOS, and visionOS are affected prior to version 26.5. Devices running any earlier iOS or iPadOS and visionOS may be vulnerable; updates in iOS 26.5, iPadOS 26.5, and visionOS 26.5 patch the issue.
Risk and Exploitability
The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, making it difficult to quantify overall exploitation probability. The CVSS score is 7.5. The likely attack vector is installation of a malicious app by the device user, based on the description. Because the flaw may not require privileged interaction, the effort to exploit is low for anyone who can author or distribute a malicious application. Organizations should assume the risk is significant until the OS is updated to a patched version.
OpenCVE Enrichment