Impact
The vulnerability arises from insufficient redaction of location data in system log entries. A malicious application can read these logs and uncover a user’s current geographic coordinates, thereby exposing personal location information. This impacts the confidentiality of personal data and could enable targeted phishing or surveillance attacks if paired with other data sources. The flaw does not provide code execution or broader system control.
Affected Systems
Apple devices running iOS 26.7, iOS 27, iPadOS 26.7, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27 are affected by the issue. The fix is delivered in the respective OS releases listed.
Risk and Exploitability
The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog. The CVSS score is 5.5, indicating moderate severity. Based on the description, it is inferred that the attack requires the installation or execution of a malicious application that gains permission to read system logs. Because the attacker needs local access and elevated log‑reading rights, the likelihood of exploitation is low but not negligible for malicious apps with sufficient privileges.
OpenCVE Enrichment