Impact
An authorization issue was discovered in Apple’s operating systems that stems from inadequate state management. The flaw permits applications to obtain sensitive user data without proper authorization, potentially exposing personal information such as contacts, photos, messages, or other privileged content. The vulnerability is classified as an authorization flaw and is mitigated by the vendor’s state management improvements.
Affected Systems
Affected Apple platforms include iOS 26.7 and iOS 27, iPadOS 26.7 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, and tvOS 27. Any device running a pre‑release version of these operating systems without the latest security update is susceptible.
Risk and Exploitability
EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of widespread exploitation. The CVE notes that an app may be able to access sensitive user data, indicating an authorization weakness that permits reading protected information without proper authorization. The exploit would presumably involve a malicious or compromised application that abuses the state management flaw. The CVE score of 5.5 reflects a moderate impact, but the low EPSS suggests that the risk of exploitation in the wild remains low. The most probable attack vector would involve a malicious application claiming legitimate privileges, but the description does not state whether the flaw requires local access or user interaction; thus, the exact risk profile cannot be precisely quantified.
OpenCVE Enrichment