Impact
The vulnerability stems from insufficient input sanitization that allows a malicious application to read protected user data. The failure results in a confidentiality breach, as attackers can extract sensitive information without requiring elevated privileges.
Affected Systems
Apple iOS, iPadOS, macOS (Sequoia, Sonoma, Tahoe), visionOS, and watchOS are affected in all releases prior to the fixes published in iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, visionOS 26.6, and watchOS 26.6.
Risk and Exploitability
The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be local or semi‑local through the installation of a malicious application that can trigger the insufficient sanitization. No remote code execution or privilege escalation is indicated; the damage is limited to data leakage within the context of the compromised app.
OpenCVE Enrichment