Impact
An inconsistent user interface issue addressed with improved state management can allow a remote attacker to manipulate the device’s internal state, enabling them to bypass network filtering controls. This flaw is medium‑severity and could let malware or unauthorized traffic traverse a device’s network filters, potentially exposing sensitive data or allowing outbound connections that should be blocked.
Affected Systems
Apple devices running iOS 26.6 or earlier, iPadOS 26.6 or earlier, macOS Sequoia 15.7.8 or earlier, macOS Sonoma 14.8.8 or earlier, macOS Tahoe 26.6 or earlier, tvOS 26.6 or earlier, visionOS 26.6 or earlier, and watchOS 26.6 or earlier are affected as noted in the vendor’s advisories.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate risk, and the EPSS score of less than 1% shows that exploitation is currently rare. The vulnerability is not listed in the CISA KEV catalog, which suggests no known widespread exploitation. Nonetheless, a remote attacker can trigger the UI inconsistency to alter network filter state, so the risk remains significant enough to warrant timely remediation. No public exploit appears to be in circulation at the time of this assessment.
OpenCVE Enrichment