Impact
The Mobile Verification Toolkit incorporates a path traversal flaw that occurs when it processes iOS backup files. Unsanitized file identifiers are concatenated into file path construction, permitting traversal outside the intended backup directory. Attackers can read any file within the MVT execution environment, potentially exposing sensitive backup data, but the flaw does not enable code execution or compromise the host system beyond the backup scope.
Affected Systems
The flaw affects the Mobile Verification Toolkit released by mvt-project. All versions prior to 2026.5.12 are vulnerable. The 2026.5.12 release contains the fix.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate risk, no EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is local: an adversary must have the ability to run MVT and supply malicious identifiers during iOS backup ingestion. This inference is drawn from the need to manipulate the tool’s internal path construction. No publicly known exploitation code or remote exploitation pathway has been observed.
OpenCVE Enrichment
Github GHSA