Impact
Based on the description, it is inferred that the vulnerability arises from a flaw in Apple’s operating‑system data‑protection mechanisms (CWE-200) that allows any installed application to read sensitive user data without proper authorization, leading to a privacy breach.
Affected Systems
Apple iOS 26.7 and 27, iPadOS 26.7 and 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, and watchOS 27 are impacted; the issue is fixed in the listed releases.
Risk and Exploitability
The CVSS score of 5.5 indicates medium severity for unauthorized disclosure of user data, while the EPSS score of < 1 % suggests a low probability of exploitation. The vulnerability is not listed in CISA KEV, meaning no publicly known exploitation tools have been documented. Based on the description, it is inferred that attackers may be able to access sensitive data without requiring elevated privileges or code execution, although the exact prerequisites are not fully detailed.
OpenCVE Enrichment