Impact
A logic flaw in Apple’s operating systems permits an application to retrieve sensitive user information. The issue stemmed from insufficient validation, a weakness commonly associated with CWE‑693. The flaw could result in confidentiality compromise if exploited by a malicious or poorly designed app.
Affected Systems
Apple devices running iOS 26.7 or earlier, iPadOS 26.7 or earlier, macOS Golden Gate 27 or earlier, macOS Sequoia 15.8 or earlier, macOS Tahoe 26.7 or earlier, tvOS 27 or earlier, and visionOS 27 or earlier are affected. Updated releases beginning with the listed versions contain the fix.
Risk and Exploitability
The vulnerability is not yet cataloged by CISA as a known exploited vulnerability, but the EPSS score indicates a less than 1% probability of exploitation. Consequently, the likelihood of exploitation is low. The CVSS score of 5.5 indicates moderate severity. The flaw can likely be triggered by any app installed on the device that is able to run with user context; precise attack vector details are not disclosed in the advisory.
OpenCVE Enrichment