Impact
The CVE description indicates that an application may gain access to a user's contact information. The flaw is an information disclosure vulnerability (CWE‑200) with a CVSS score of 5.5, representing moderate impact on confidentiality. The issue was addressed with improved permission checks, but until the fix is applied, a malicious or poorly coded app could read private contact data without the user’s explicit consent.
Affected Systems
Apple iOS, iPadOS, and macOS devices running any build earlier than iOS 18.7.10, iOS 26.6, iPadOS 18.7.10, iPadOS 26.6, or macOS Tahoe 26.6 are susceptible. The issue is fixed in iOS 18.7.10, iOS 26.6, iPadOS 18.7.10, iPadOS 26.6, and macOS Tahoe 26.6 as announced by Apple.
Risk and Exploitability
The EPSS score of less than 1 % suggests that active exploitation is unlikely, and the flaw is not listed in CISA KEV. Based on the description, the likely attack vector is an application that installs on a device—through the App Store or a third‑party source—and uses the Contacts API to read data without prompting the user. While exploitation risk is low, the potential for privacy‑breach remains.
OpenCVE Enrichment