Impact
A missing entitlement check in Apple operating systems allows an application to gather device‑specific identifiers, enabling the application to fingerprint the user. The flaw stems from insufficient verification of system entitlements before exposing identifying information. The potential impact is that an attacker could uniquely track a device or correlate data across services, compromising user privacy.
Affected Systems
Apple devices running iOS, iPadOS, tvOS, visionOS, and watchOS before version 27 are affected. The vulnerability is addressed in iOS 27, iPadOS 27, tvOS 27, visionOS 27, and watchOS 27.
Risk and Exploitability
It has a low EPSS score of < 1%, indicating a very low but non‑zero probability of exploitation, and it is not included in the CISA KEV catalog. The CVSS score of 7.5 marks this vulnerability as moderate to high severity, underscoring the privacy risk from user fingerprinting. The flaw can be leveraged by any application that obtains device identifiers on affected systems, enabling unique tracking of the device or correlation of data across services.
OpenCVE Enrichment