Impact
When a maliciously crafted contact file is imported or processed, the software does not validate the input properly, allowing an attacker to read sensitive personal information that should remain confidential. The weakness resides in the data handling path for contact objects and can result in unauthorized disclosure of addresses, phone numbers, email addresses, and other personal data stored on the device. Based on the description, it is inferred that the failure in validation is the root cause of the information leakage.
Affected Systems
Apple iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, visionOS 26.6, and watchOS 26.6.
Risk and Exploitability
The vulnerability is not listed in the CISA KEV catalog. The EPSS score of <1% indicates a very low probability of exploitation, but the impact remains significant if exploited. The likely attack vector is an attacker delivering a specially crafted contact file via email, messaging, or a compromised application; when the user opens or imports the file, the erroneous processing routine is triggered, causing data disclosure rather than code execution.
OpenCVE Enrichment