Impact
The vulnerability arises from a logic flaw in Apple’s operating system validation that allows an installed application to bypass the network restrictions normally enforced. The flaw stems from missing validation that should prevent outbound connections to disallowed domains or services. If an attacker installs or modifies a legitimate application, they could transmit data beyond the intended network boundaries, potentially compromising data confidentiality. The likely attack vector is that an attacker must first install or modify a mobile application on the target device, after which the bypass can be realized.
Affected Systems
Apple hardware running iOS, iPadOS, macOS, visionOS, or watchOS prior to major release 27 are vulnerable. The official fix was deployed with iOS 27, iPadOS 27, macOS Golden Gate 27, visionOS 27, and watchOS 27, meaning any device on earlier major releases remains susceptible. Devices running the 27 or later releases are considered not vulnerable.
Risk and Exploitability
The CVSS base score of 4.4 indicates moderate severity, but the EPSS score of less than 1% still indicates a low probability that this flaw will be exploited. The vulnerability is not listed in CISA’s KEV catalog, suggesting no widespread public exploitation. Exploitation requires an attacker to have a foothold on the device through the installation or modification of an application, which limits the attack surface compared to remote or network-based exploits.
OpenCVE Enrichment