Impact
The reported vulnerability is a permissions flaw that permits an application to write to protected sections of the file system. This flaw can let a malicious or compromised app alter critical system or application files, potentially enabling privilege escalation and tampering with device configuration. The weakness is classified as CWE‑732, representing the inability to correctly enforce discretionary access controls.
Affected Systems
Apple iOS and iPadOS versions prior to 26.7 and 27, and Apple macOS releases before Golden Gate 27, Sequoia 15.8, and Tahoe 26.7 are affected. Devices running those OS versions are susceptible until the vulnerability is resolved through an update.
Risk and Exploitability
The EPSS score of less than 1% signals that exploitation is currently considered unlikely, and the vulnerability is not listed in CISA’s KEV catalog. The CVSS score of 5.5 indicates moderate impact. Based on the description, it is inferred that an attacker would need to install a malicious application on the device, making this a local or installation‑based attack vector. With no publicly available exploits, the risk largely lies in the potential impact should the flaw be abused by a privileged app. The mitigation is most effectively achieved by upgrading the operating system to a patched release.
OpenCVE Enrichment