Impact
An unauthorized attacker can learn sensitive data from the Microsoft Teams iOS application, as the vulnerability allows disclosure of information over a network. The flaw represents an instance of information disclosure (CWE-200), meaning that personal or confidential data may be leaked while the app is operating on a mobile device.
Affected Systems
Microsoft Teams for iOS is affected; specific build numbers are not listed, so any installed version of the Teams mobile client could potentially be susceptible until the vendor releases an updated application.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity vulnerability, and the EPSS score is not available, so the probability of exploitation is unclear. The CVE is not listed under the CISA KEV catalog, suggesting no known large‑scale deployments of active exploits. The likely attack vector is over the network because the disclosure occurs when the app communicates with Microsoft’s servers, but this is inferred from the description and not explicitly documented.
OpenCVE Enrichment