Impact
Apple has identified an issue where input sanitization is insufficient, enabling a malicious application to read protected user data without needing elevated privileges. The flaw exists across several operating system releases and is fixed by the updates for iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, visionOS 26.6, and watchOS 26.6. Attackers can exploit this to leak confidential data within the context of the compromised app.
Affected Systems
Apple iOS, iPadOS, macOS (Sequoia, Sonoma, Tahoe), visionOS, and watchOS are affected in all releases prior to the listed fixes.
Risk and Exploitability
The EPSS score is < 1 % and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be local or semi‑local through the installation of a malicious application that triggers the insufficient sanitization. No remote code execution or privilege escalation is indicated; the damage is limited to data leakage within the context of the compromised app.
OpenCVE Enrichment