Impact
A permissions flaw due to inadequate path validation can allow a sandboxed application to access files outside its intended scope. This path‑traversal weakness enables the app to read or modify restricted files on the device, potentially compromising confidential data and altering system integrity. The impact is limited to the device but can degrade overall reliability if critical files are altered.
Affected Systems
Apple operating systems affected include iOS 26.7 and later, iPadOS 26.7 and later, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, and visionOS 27 and later. Devices running those OS versions may be vulnerable until updated.
Risk and Exploitability
The CVSS score of 5.5 reflects moderate severity, and the EPSS score of < 1 % suggests a very low probability of active exploitation. The vulnerability is local, requiring a sandboxed or malicious app to exploit the path‑validation flaw, and is not an over‑the‑network attack vector. It is not listed in CISA’s KEV catalog.
OpenCVE Enrichment