Impact
An improper state management flaw in iOS and iPadOS allows an attacker with physical access to capture sensitive user information during iPhone Mirroring sessions, resulting in a confidentiality breach.
Affected Systems
Apple iOS and iPadOS devices running versions prior to 26.6; these versions are affected and the issue is fixed in iOS 26.6 and iPadOS 26.6.
Risk and Exploitability
The vulnerability requires physical proximity to the device and exploits inadequate state handling during mirroring; its exploitation depends on the attacker controlling the device environment, making it a local-attack vector. The EPSS score is lower than 1% (approximately 0.0015) and the vulnerability is not listed in CISA KEV, indicating that it is not known to be actively exploited yet, but the confidentiality risk remains high for users who mirror content.
OpenCVE Enrichment