Impact
The flaw resides in the operating system’s data protection framework, permitting malicious or compromised applications to retrieve a persistent device identifier. This identifier can be used to track, profile, or link a user across services, thereby exposing sensitive personal information beyond what an application is authorized to access. The vulnerability exemplifies a sensitive information exposure weakness, with the potential to compromise user privacy.
Affected Systems
Apple iOS, iPadOS, macOS (Sequoia 15.7.8, Sonoma 14.8.8, Tahoe 26.6), tvOS, visionOS, and watchOS are affected. The fix has been released in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6. Devices running earlier releases remain vulnerable.
Risk and Exploitability
No public exploit has been reported and the EPSS score is <1%; the vulnerability is not cataloged in CISA KEV. Nonetheless, the risk of data exposure is significant, especially if a malicious or compromised application can be installed. The likely attack vector is the introduction of an app with elevated data‑access privileges, either through the App Store, sideloading, or other means. With no current exploit evidence, the threat appears moderate to high based solely on the potential impact on data confidentiality.
OpenCVE Enrichment