Impact
An authorization flaw stemming from improper state management permits a malicious or compromised application to access sensitive user data. The vulnerability is resolved in all 26.6 releases of the Apple operating systems. If exploited, the flaw could allow the application to read or alter privileged data, thereby compromising the confidentiality and integrity of user information.
Affected Systems
The flaw impacts Apple platforms, including iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. All devices running a version prior to 26.6 are vulnerable, until the respective 26.6 updates are installed.
Risk and Exploitability
EPSS score is <1% and KEV is not listed, so the probability of current exploitation is low. The CVSS score of 6.5 indicates significant impact. The vulnerability involves unauthorized data access, indicating a high potential impact if an attacker can install or persuade a user to run a malicious application. The attack requires local or user‑trusted app execution; no remote exploit path is documented.
OpenCVE Enrichment