Impact
A logic flaw in the operating systems can be exploited by a third‑party application to access and disclose sensitive user information. The flaw involves missing or insufficient checks that allow the application to read data that it should not be able to view. The result is the potential disclosure of personal data, which could be used for identity theft or other malicious purposes.
Affected Systems
Apple iOS and iPadOS versions prior to 26.6.1 and macOS Tahoe prior to 26.6.2 contain the logic issue. The fix, introduced in iOS 26.6.1, iPadOS 26.6.1, and macOS Tahoe 26.6.2, adds improved checks to prevent the leak.
Risk and Exploitability
Because the EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog, the likelihood of active exploitation remains uncertain. The attack appears to require local execution by an installed application, indicating that a malicious or compromised app could trigger the data leak. No public exploitation evidence or known exploit code is documented in the provided information.
OpenCVE Enrichment