Impact
The vulnerability is a permissions issue that could allow an application to read or modify sensitive user data it should not be able to, potentially leading to privacy compromise. The flaw arises from insufficient restriction of app capabilities, permitting access to information normally reserved for system processes.
Affected Systems
Apple iOS and iPadOS devices running versions earlier than 27 are impacted; the issue is fixed in iOS 27 and iPadOS 27.
Risk and Exploitability
The EPSS score is < 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in CISA KEV. The CVSS score is 5.5, indicating moderate severity. The likely attack vector involves a malicious or compromised application that exploits the permissions oversight to obtain protected data. As such, the risk remains moderate until a patch is applied.
OpenCVE Enrichment