Impact
An authorization flaw allows an application to read or modify sensitive user data on Apple devices. The weakness stems from a misconfiguration of access controls that was corrected in a recent security update. An attacker who can install a malicious application on a device could exploit the vulnerability to gain data that should be protected by the operating system's privacy safeguards.
Affected Systems
Apple iOS and iPadOS builds older than 26.7 and 27, and Apple macOS releases prior to macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7 are affected. The vulnerability was resolved in the releases cited above; systems running earlier OS versions are exposed.
Risk and Exploitability
The EPSS score of < 1% indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, indicating no publicly known large-scale exploitation at present. However, because the flaw permits local applications to bypass operating‑system controls, a malicious or compromised app could act under the guise of a legitimate process to harvest personal data. The absence of a publicly available exploit vector suggests that the attack requires the attacker to deliver a harmful application to the target device, but once that occurs, the potential for data exfiltration is significant.
OpenCVE Enrichment