Impact
A logic issue in macOS, iOS, and iPadOS internal checks allows an application to locate and read sensitive user data that should not be accessible. The flaw was identified and addressed by adding stricter validation, and the vulnerability is fixed in iOS 18.7.10, iPadOS 18.7.10, Sequoia 15.7.8, Sonoma 14.8.8, and Tahoe 26.6. Until the update is installed, a malicious or compromised app could read protected data. Based on the description, it is inferred that the flaw can be exploited by a local application without additional conditions.
Affected Systems
Affected are Apple macOS releases prior to the security patches: Sequoia 15.x, Sonoma 14.x, and Tahoe 26.x, as well as iOS and iPadOS versions earlier than 18.7.10. The issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, iOS 18.7.10, and iPadOS 18.7.10. Systems running earlier minor or patch versions of these major releases are considered vulnerable.
Risk and Exploitability
The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, suggesting that known exploitation activity is low. The flaw in macOS, iOS, and iPadOS can be leveraged by a malicious application or a local attacker to retrieve protected data. The likely attack vector is inferred to be a local application exploiting the logic flaw. The attack vector is most likely local; remote exploitation would require additional conditions that are not documented. While no active exploits are documented, the vulnerability represents a medium risk until mitigated. The CVSS score of 5.5 indicates medium severity, and this rating combined with the low EPSS confirms the moderate potential impact.
OpenCVE Enrichment