Impact
An authorization issue was addressed with improved state management. The vulnerability allows an application to bypass normal authorization checks and read or otherwise access sensitive user data that should be protected. The weakness is categorized as CWE‑285, an authorization error. The impact is the potential exposure of confidential information such as credentials, health records, or location data. Based on the description, it is inferred that no specific preconditions beyond a malicious or compromised application are required, so an attacker could abuse the flaw by installing or modifying an app on the device.
Affected Systems
Affects all Apple operating systems—iOS, iPadOS, tvOS, visionOS, and watchOS—before the release of version 27 for each platform. Devices running any of the older releases are vulnerable.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, and the EPSS score of <1% shows a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, further indicating that it is not being actively exploited. Attackers could exploit the flaw by delivering a malicious or modified application through legitimate or third‑party app distribution channels, a scenario that is realistic given the ubiquity of app stores. While the risk is not high, the potential impact on confidentiality warrants attention. No known workaround is available, so the only practical defense is to update devices to the patched versions.
OpenCVE Enrichment