Impact
When a maliciously crafted contact file is imported or processed, the software does not validate the input properly, allowing an attacker to read sensitive personal information that should remain confidential. The weakness resides in the data handling path for contact objects and can result in unauthorized disclosure of addresses, phone numbers, email addresses, and other personal data stored on the device. Based on the description, it is inferred that the failure in validation is the root cause of the information leakage.
Affected Systems
Affected systems include Apple iOS versions 18.7.10 and 26.6, iPadOS versions 18.7.10 and 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, visionOS 26.6, and watchOS 26.6.
Risk and Exploitability
The vulnerability is not listed in the CISA KEV catalog. The EPSS score of <1% indicates a very low probability of exploitation, but the impact remains significant if exploited. The CVSS base score of 5.5 classifies this flaw as moderate severity, reflecting a potential for moderate impact on confidentiality and integrity. The likely attack vector involves an attacker delivering a maliciously crafted contact file via email, messaging, or a compromised application; when the user opens or imports the file, the flawed processing routine is triggered, causing sensitive data disclosure rather than code execution.
OpenCVE Enrichment