Impact
The vulnerability is an authorization flaw that allows an application to access sensitive user data that it should not be able to read. Apple mitigated the issue by improving state management, which was addressed in iOS 26.6, iPadOS 26.6, and macOS Tahoe 26.6. Prior to those releases, an app could exploit the flaw to read private information, potentially compromising user confidentiality.
Affected Systems
Affected systems are Apple devices running iOS or iPadOS prior to version 26.6 and macOS Tahoe prior to 26.6. The flaw applies to all models supporting those operating systems and could be leveraged by any third‑party application that is installed on the device.
Risk and Exploitability
Because the EPSS score is less than 1% and the CVSS score is 5.5, the likelihood and impact are moderate. The flaw allows an attacker who installs a malicious or compromised application to read sensitive user data, resulting in likely need to persuade a user to install the malicious app; direct exploitation without user action is not mentioned. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment