Impact
A path handling flaw allows an application to write to protected areas of the device’s filesystem, enabling an attacker to overwrite system files or directories. The vulnerability arises from insufficient validation of the path component during file resolution, which permits the creation of paths that traverse into privileged directories. Because the attacker can modify critical files, the flaw could compromise system integrity and potentially lead to further privilege escalation or denial of service.
Affected Systems
Apple iOS and iPadOS on versions earlier than 26.7 and 27, and visionOS on versions earlier than 27, are affected. The issue is fixed in iOS 26.7 and 27, iPadOS 26.7 and 27, and visionOS 27.
Risk and Exploitability
The flaw is local; it requires the execution of an unsanctioned application on the device, which is a realistic attack vector for malicious or compromised third‑party apps. The CVSS score of 5.5 indicates medium severity, and the EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. However, if exploitation occurs, the ability to modify protected filesystem locations presents a significant integrity impact and the potential for downstream privilege escalation.
OpenCVE Enrichment