Impact
A permissions flaw removes critical restrictions allowing a malicious application to escape its sandbox, potentially granting unauthorized access to system resources and the ability to execute additional code. This type of vulnerability can lead to full compromise of the device, changing the confidentiality, integrity, and availability of data and services on the affected operating system. The issue is resolved in the upcoming releases.
Affected Systems
Apple iOS, iPadOS, and macOS are affected. Devices running any version prior to iOS 27, iPadOS 27, or macOS Golden Gate 27 may be vulnerable.
Risk and Exploitability
The exploit is likely to be possible via a malicious app installed on the device; it requires local installation and does not rely on external network vectors. The EPSS score is less than 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, a sandbox escape carries a high severity impact because it allows an attacker to gain unauthorized access to system resources and execute further code.
OpenCVE Enrichment