Impact
The vulnerability is a flaw in the operating system’s state management that allows an attacker with physical access to a device that is currently unlocked to view stored Wi‑Fi passwords without any authentication or authorization. Once the device is unlocked, the defect bypasses normal credential checks and exposes sensitive network credentials, which could enable the attacker to connect to, spoof, or misuse wireless networks.
Affected Systems
Apple devices running iOS or iPadOS prior to version 27 are affected. The fix is included in iOS 27 and iPadOS 27, so any device on an earlier release is potentially vulnerable.
Risk and Exploitability
The attack requires physical possession of an unlocked device, so it is a local, limited‑scope vulnerability. The EPSS score indicates a low but nonzero exploitation probability of less than 1%, and the issue is not listed in CISA's KEV. Updating to the patched OS or ensuring the device remains locked before use mitigates the risk.
OpenCVE Enrichment