Impact
The vulnerability arises from incomplete privacy safeguards in the file‑handling routines of Apple’s operating systems. When an application writes or opens certain files, it can read data that it is not authorized to access, exposing sensitive user information. This flaw fits the CWE‑200 classification of improper information disclosure.
Affected Systems
All releases of Apple iOS, iPadOS, and visionOS before version 27 are affected. The issue has been addressed in iOS 27, iPadOS 27, and visionOS 27.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate risk, and the EPSS score of less than 1 % implies a low probability of widespread exploitation at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Attackers are likely limited to local mobile applications or contexts where an app has permission to place and read protected files; no remote exploitation vector has been documented. The impact is restricted to confidentiality and does not appear to affect integrity or availability.
OpenCVE Enrichment