Impact
The vulnerability arises from improper handling of persistent identifiers, allowing an app to correlate a user’s identity across uninstallations and reinstallations. An attacker could use this flaw to build a long‑term profile of a user without consent. The weakness involves the improper persistence and misuse of sensitive identifiers, reflected in the known CWEs 287, 330, and 359.
Affected Systems
Apple’s operating systems—iOS, iPadOS, macOS Golden Gate, and visionOS—are affected. Devices running any pre‑27 release are vulnerable until the identifier‑handling fix appears in version 27. Users on newer versions are not impacted.
Risk and Exploitability
The EPSS score of less than 1 % indicates a very low exploitation likelihood, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 7.5 classifies this flaw as High severity, meaning a successful exploitation could have a significant impact on user privacy. The likely attack vector is a malicious or compromised app that requests the advertising or device identifier. The exploit does not require elevated privileges or compromise of system integrity, and the primary risk remains a privacy violation rather than direct system compromise.
OpenCVE Enrichment