Impact
An authorization flaw in Apple’s state management logic may let a locally running application read sensitive data that it should not access. The weakness originates from improper access control (CWE‑285) and inadequate enforcement of state integrity (CWE‑863). When exploited, an application could obtain personal information beyond its intended scope.
Affected Systems
Apple’s mobile and desktop operating systems are impacted. Versions before iOS 27, iPadOS 27, and tvOS 27 are vulnerable, as are macOS releases older than Golden Gate 27, Sequoia 15.8, and Tahoe 26.7. visionOS and watchOS are also affected until version 27 is installed.
Risk and Exploitability
The CVSS score is 5.5 and the EPSS score is below 1%, indicating a moderate potential severity and low likelihood of widespread exploitation. The flaw is not listed in the CISA KEV catalog. Attack vector is inferred to be local; a privilege‑bearing application that can run on the device may exploit the mishandled state to access data normally protected.
OpenCVE Enrichment