Impact
An authorization flaw allowing an application to read sensitive user data was discovered. The vulnerability stems from improper state management that fails to enforce access controls, giving a malicious or compromised app access to data normally restricted to the device or user. This flaw can lead to confidentiality breaches by exposing personal information without consent from the user or operating system. The weakness is consistent with known improper access control weaknesses.
Affected Systems
Apple iOS versions earlier than 26.7 or 27, iPadOS versions earlier than 26.7 or 27, tvOS versions earlier than 27, and visionOS versions earlier than 27 are vulnerable. Devices with those older operating systems are at risk if they are not running the latest service releases. The fix is included in iOS 26.7 and later, iPadOS 26.7 and later, tvOS 27, and visionOS 27.
Risk and Exploitability
The CVSS score is 5.5; the EPSS score <1%, indicating a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation yet. The attack vector is likely local, via an application that could be malicious or compromised on the device. The flaw involves improper state management within the OS that bypasses access controls, enabling an app to read sensitive user data.
OpenCVE Enrichment