Impact
Apple identified an improved access control that inadvertently left an authorization gap, allowing applications to read persistent device identifiers that should remain protected. The flaw does not give attackers code execution or other direct system control but exposes a set of uniquely identifying values that could be used for tracking, profiling or other privacy‑compromising purposes. This is effectively a data‑exposure vulnerability, exposing sensitive device information without proper authentication or permission checks.
Affected Systems
The issue affects multiple Apple operating systems, including iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. Specifically, affected versions are iOS 26.7 and 27, iPadOS 26.7 and 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27.
Risk and Exploitability
Because the flaw centers on improper access control, the primary exploitation path involves a malicious or compromised application that is granted any user‑level installation. Once installed, the app can request the device’s persistent identifiers and read them without further user consent. The CVSS score of 5.5 indicates moderate severity, the EPSS score is < 1% and the vulnerability is not currently listed in the CISA KEV catalog, indicating a low probability of exploitation, yet the privacy impact remains significant, especially where unverified applications may be installed.
OpenCVE Enrichment