Impact
A permissions flaw removes critical restrictions allowing a malicious application to escape its sandbox, potentially granting unauthorized access to system resources, sensitive data, and the ability to execute additional code. This type of vulnerability can lead to full compromise of the device, changing the confidentiality, integrity, and availability of data and services on the affected operating system. The description indicates the issue is resolved in the upcoming releases.
Affected Systems
Apple iOS, iPadOS, and macOS are affected. Devices running any version prior to iOS 27, iPadOS 27, or macOS Golden Gate 27 may be vulnerable. The vendor has platform.
Risk and Exploitability
The exploit is likely to be possible via a malicious app installed on the device; it requires local installation and does not rely on external network vectors. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, but the impact of a sandbox escape justifies a high severity rating. Apple has mitigated the risk by enforcing the fix in the upcoming OS releases.
OpenCVE Enrichment