Impact
A weakness in how Apple operating systems verify application permissions allows a locally‑installed application to bypass normal access controls and read user‑sensitive data that it should not be able to access. The flaw is identified as an access control vulnerability, meaning an attacker can obtain confidential information through an unauthorized app.
Affected Systems
Apple iOS, iPadOS, macOS Tahoe, and visionOS versions earlier than 26.6 are affected. Devices running any of these operating systems at a vulnerable version can be compromised by installing an app that takes advantage of the improper checks.
Risk and Exploitability
The EPSS score is less than 1%, and the CVSS score is 5.5, indicating a moderate severity. The vulnerability is not listed in CISA KEV, so there are no known in‑the‑wild exploits. Likely attack vectors involve local installation or sideloading of applications that can read protected data. The confidentiality impact is significant, but the overall risk is mitigated by the low exploitation likelihood and the requirement that the device run a vulnerable OS version.
OpenCVE Enrichment