Impact
The vulnerability is a permissions issue that was mitigated with additional sandbox restrictions. An application on the device may be able to collect data sufficient to fingerprint the user, potentially exposing sensitive personal information. This flaw does not allow code execution or system compromise, but it increases privacy risk by enabling user tracking.
Affected Systems
Apple devices running iOS, iPadOS, macOS Golden Gate, visionOS, or watchOS with any version older than 27 are affected. The fix is delivered through OS updates version 27 or later.
Risk and Exploitability
EPSS score is < 1%, and the vulnerability is not listed in CISA KEV, indicating a very low likelihood of exploitation yet. Attackers would need to distribute a malicious or compromised app, which can then exploit the sandbox to fingerprint the user. The risk is mostly privacy‑related and depends on the presence of such apps in the user’s environment.
OpenCVE Enrichment