Impact
An information disclosure flaw was addressed by removing the vulnerable code. The flaw could allow an application to read sensitive user data that it should not be able to access. The vulnerability potentially compromises user privacy and the confidentiality of personal information. The description indicates that any app that exploits the flaw could obtain data beyond its intended scope.
Affected Systems
The issue affected Apple operating systems prior to version 26.6: iOS, iPadOS, macOS Tahoe, tvOS, and watchOS. Versions earlier than 26.6 are vulnerable; the fix is present in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, and watchOS 26.6.
Risk and Exploitability
The CVSS score is 5.5, and the EPSS score is less than 1%, indicating moderate severity but a very low likelihood of exploitation. This vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local, where an app or malicious code on the device could trigger the flaw to read protected data. Because the issue was mitigated by code removal, no patch payload exists beyond upgrading to 26.6. If the system remains on a vulnerable version, an attacker with local or application-level access may extract sensitive data.
OpenCVE Enrichment