Impact
An improper permission validation flaw allows any installed application to delete files it normally could not access. The vulnerability is present in iOS, iPadOS, macOS (Sequoia, Sonoma, Tahoe), and visionOS, and is fixed in iOS and iPadOS 18.7.10 and 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, and visionOS 26.6, giving non-privileged apps the ability to carry out file deletion operations that violate the operating system’s access controls.
Affected Systems
Apple devices running iOS, iPadOS, macOS (Sequoia, Sonoma, Tahoe), or visionOS that are on releases earlier than iOS and iPadOS 18.7.10, iOS and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, or visionOS 26.6 remain vulnerable. Devices on or later than these releases are protected by the fix. The vulnerability is tied to the operating systems themselves, with no specific third‑party software implicated.
Risk and Exploitability
The EPSS score is < 1%, indicating a low but non‑zero exploitation likelihood, and the CVE is not listed in the CISA KEV catalog. The CVSS base score of 5.5 reflects a moderate severity, indicating that improper permission validation could allow any installed application to delete protected files, leading to data integrity and availability impacts. The flaw is an improper access control weakness; an attacker whose app can execute code on the device (e.g., through user‑installed software) could delete protected files. The likely attack vector is a local or user‑initiated one where the attacker supplies or installs a malicious app that gains elevated privileges within the Apple ecosystem. Based on the description, the vulnerability allows denial of service and data modification to files the app should not access.
OpenCVE Enrichment