Impact
A permissions flaw in Apple operating systems allows applications to bypass required checks and read user-sensitive data they should not access. The issue is a classic access‑control weakness (CWE‑284), resulting in confidentiality violations but does not grant code execution or other forms of privilege escalation.
Affected Systems
Apple devices running iOS, iPadOS, or macOS versions prior to the releases that incorporate the fix are vulnerable. The patch was applied in iOS 26.7, iOS 27, iPadOS 26.7, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7, so any device operating on an earlier version is at risk.
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of exploitation. Based on the description, an attacker would need to install or modify an application on the device to exploit the missing permission checks. The attack vector is most likely local, requiring a malicious or compromised app, and no publicly documented exploits are cited in the provided references.
OpenCVE Enrichment