Impact
A path handling issue, addressed via improved validation, may allow an application to access files beyond intended directories. This flaw can lead to the disclosure of user‑sensitive data. The weakness is a classic path traversal vulnerability, categorized as CWE‑22.
Affected Systems
Affecting Apple iOS and iPadOS releases prior to version 27, Apple macOS releases before Golden Gate 27, Sequoia 15.8, or Tahoe 26.7. Users of these older operating systems are potentially exposed. The defect has been corrected in the listed later releases.
Risk and Exploitability
The CVSS score is 5.5. The EPSS score is approximately 0.18%, indicating a very low probability of exploitation. The KEV status is not listed, so no documented exploitation is known. Based on the description, the likely attack vector is local or controlled use of an application that handles arbitrary file paths. The flaw could allow a privilege‑constrained attacker to read files beyond intended directories by manipulating path inputs, potentially exposing user‑sensitive data.
OpenCVE Enrichment