Impact
The vulnerability is a path traversal flaw (CWE-22) that can be exploited. Because the flaw is mitigated through improved path validation, the attack requires the device to be physically accessed and trust‑paired with an attacker’s machine. The overarching impact is that attackers could compromise the confidentiality and integrity of user data and configuration files if they obtain physical possession, indicating a very low probability of exploitation, and the vulnerability is not listed in KEV and limits attacks to a local context, but still allows full file read/write capability on that device.
Affected Systems
Apple iOS and iPadOS devices are affected. The flaw was addressed in iOS 26.7, iOS 27, iPadOS 26.7, and iPadOS 27.
Risk and Exploitability
The flaw allows reading and writing arbitrary files with physical access to a trust‑paired device physically present and paired with the target device, limiting the attack surface to local environments. The CVSS score of 7.5 indicates high severity, and the EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. If an attacker meets the conditions, they could read sensitive personal data and alter system configuration, potentially leading to credential theft or further local compromise.
OpenCVE Enrichment