Impact
The CVE describes an access issue where an application can read files outside its sandbox due to insufficient access restrictions. This flaw allows a malicious or compromised app to retrieve sensitive data that belongs to other apps or to the system, potentially exposing confidential information. Because the vulnerability arises from weak sandbox enforcement, it represents an information‑disclosure weakness.
Affected Systems
Affected Apple products include Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. Applications running on versions prior to Safari 26.6, iOS 18.7.10, iPadOS 18.7.10, iOS 26.6, iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6 are vulnerable. The patch in 26.6 and later addresses the issue for each platform.
Risk and Exploitability
The vulnerability is local, requiring an application already installed on the device to exploit it, and permits reading files outside the intended sandbox due to inadequate access restrictions. The CVSS score of 6.5 indicates medium severity. The EPSS score indicates a very low exploitation probability (< 1%) and the vulnerability is not listed in CISA’s KEV catalog, implying it has not yet been widely leveraged. Nonetheless, the ability to read data beyond the sandbox raises the risk of confidential data exposure, especially on shared devices or in enterprise environments. Mitigating this risk requires prompt application of the vendor‑issued updates.
OpenCVE Enrichment