Impact
A permissions flaw in multiple Apple operating systems allows an installed application to read sensitive user data that it should not be able to access. The vulnerability was mitigated by adding restrictions in later releases. The impact is the disclosure of personal or device‑specific information to an unauthorized application.
Affected Systems
Apple iOS, iPadOS, macOS, tvOS, visionOS, and watchOS are affected. The fix is implemented in iOS 26.7, iOS 27, iPadOS 26.7, iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, and watchOS 27. Devices running earlier versions of these operating systems remain vulnerable.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. The EPSS score of less than 1% suggests a very low probability of exploitation in the general population. The vulnerability is not listed in CISA’s KEV catalog. The attack vector appears to be local, requiring an installed or compromised app with elevated privileges to exploit the flaw; however, this is inferred from the description and not confirmed. No publicly reported exploitation examples are known as of the data available.
OpenCVE Enrichment