Impact
A path handling flaw can allow an application to write to protected areas of the device’s filesystem. The flaw arises from insufficient input validation during file path resolution, permitting unauthorized modification of sensitive files or directories. Because the affected components are protected by the operating system, an attacker can alter system data, potentially compromising integrity and leading to further privilege escalation. The description explicitly notes the potential for apps to modify protected parts of the file system.
Affected Systems
Apple’s mobile and desktop operating systems, including iOS and iPadOS on versions prior to 26.7 and 27, and visionOS prior to 27, are affected. The issue is patched in iOS 26.7 and 27, iPadOS 26.7 and 27, and visionOS 27.
Risk and Exploitability
The vulnerability is local in nature; it requires an app to be run on the device, which is a reasonable attack vector for malicious or compromised applications distributed through the App Store or other channels. The EPSS score is not available, but the lack of a KEV listing does not diminish the potential impact, as the flaw still allows modification of protected filesystem areas. The absence of a specific CVSS score precludes a precise severity rating, yet the described capability of altering system files indicates high potential damage for confidentiality, integrity, and availability.
OpenCVE Enrichment