Impact
A logic flaw in Apple’s operating systems allows an application to potentially read and disclose sensitive user data because of missing validation checks. The flaw is a failure of the system protection mechanism, identified as CWE‑693, which can compromise confidentiality. The issue is resolved in specific updates but remains exploitable on devices that have not installed them.
Affected Systems
Affected systems include Apple iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8 and macOS Tahoe 26.6.2, as well as tvOS 27, visionOS 27, and watchOS 27. Devices running earlier versions before these releases are vulnerable. All relevant Apple platforms are enumerated in the CNA vendor‑product list.
Risk and Exploitability
The CVSS base score of 5 indicates moderate severity, while the EPSS score of less than 1% and absence from CISA’s KEV catalog suggest a low likelihood of active exploitation. No publicly available exploit or evidence of ongoing attacks is documented, and the attack vector is not specified in the advisory, so the vulnerability may require local or privileged access to a target device. The risk to user privacy remains until devices are updated.
OpenCVE Enrichment