Impact
A logic flaw in the operating systems can be exploited by a third‑party application to access and disclose sensitive user information. The flaw involves missing or insufficient checks that allow the application to read data that it should not be able to view. The result is the potential disclosure of personal data, which could be used for identity theft or other malicious purposes.
Affected Systems
Apple iOS and iPadOS versions prior to 26.6.1 and macOS Tahoe prior to 26.6.2 contain the logic issue. The fix, introduced in iOS 26.6.1, iPadOS 26.6.1, and macOS Tahoe 26.6.2, adds improved checks to prevent the leak.
Risk and Exploitability
Because the EPSS score is <1% and the vulnerability is not listed in the CISA KEV catalog, the likelihood of active exploitation remains uncertain. The CVSS score of 5 indicates a moderate severity. The available information does not specify the attack vector or prerequisites for exploitation. No public exploitation evidence or known exploit code is documented in the provided information.
OpenCVE Enrichment