Impact
An authorization flaw in Apple devices’ Bluetooth module permits an application to access Bluetooth functionality without the necessary permissions. The vulnerability arises from insufficient state management that allows a malicious or poorly designed app to bypass the normal authorization checks before opening Bluetooth APIs. If an attacker can execute code that triggers this flaw, they could initiate connections, send or harvest data from nearby Bluetooth devices, potentially compromising the confidentiality and integrity of information transmitted over Bluetooth and affecting device operation.
Affected Systems
Apple iOS, iPadOS, macOS Golden Gate, tvOS, visionOS, and watchOS are affected by this flaw. It exists in all releases prior to version 27 on each platform and has been remediated in iOS 27, iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, and watchOS 27.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity, and the EPSS score is below 1%, with no listing in CISA’s KEV catalog, indicating limited publicly available exploitation data. Exploitation requires that an attacker be able to run malicious code on the device, typically via a malicious application or local compromise. Under those circumstances the risk is moderate, as unauthorized Bluetooth connectivity could lead to data leakage or device compromise.
OpenCVE Enrichment