Impact
The vulnerability originates from a missing permission check, allowing an application to access sensitive user data without appropriate authorization. This weakness exemplifies improper authorization (CWE-269) and could let an app read protected data beyond its granted permissions. Based on the description, it is inferred that the likely attack vector is the installation or running of a malicious application that exploits this missing permission check to read protected data.
Affected Systems
All builds of Apple’s iOS, iPadOS, visionOS, and watchOS prior to version 27 are affected. Devices running iOS 27, iPadOS 27, visionOS 27, or watchOS 27 are not affected, as the missing permission restrictions have been fixed.
Risk and Exploitability
The EPSS score is less than 1 % and the vulnerability is not listed in CISA’s KEV catalog, indicating a low probability of exploitation. The flaw permits applications to read protected data when the user installs or runs the app, creating a confidentiality risk. The CVSS score of 5.5 indicates that the vulnerability poses a moderate threat.
OpenCVE Enrichment