Impact
The vulnerability stems from an authorization flaw that allows an application to read motion sensor data from headphones without the user’s consent. This improper access control results in an information disclosure that could be used for privacy violations, such as tracking the user’s movements or inferring sensitive behavior. The weakness is categorized under missing authorization for headphone motion data (CWE‑863).
Affected Systems
The flaw affects Apple devices running iOS, iPadOS, macOS, tvOS, and watchOS versions that are earlier than the patched releases. Apple lists the fix in iOS 26.7 and 27, iPadOS 26.7 and 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, and watchOS 27. Devices running any of these or newer versions are not affected.
Risk and Exploitability
The CVSS score is 5.5, indicating moderate severity, while the EPSS score is less than 1 %, suggesting a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an application with the ability to interact with the headphone interface could exploit the flaw to access motion data without consent. The attack vector is not explicitly documented, but it likely requires local or privileged installation of an application on the device. Due to the privacy sensitivity of motion data, the potential impact remains significant, even though exploitation probability is low.
OpenCVE Enrichment