Impact
A permissions issue was discovered in several Apple operating systems that allowed an application to access sensitive user data. The flaw stems from improper authorization controls and is classified as a CWE-269 weakness. The vulnerability is fixed in iOS 27, iPadOS 27, macOS Golden Gate 27, tvOS 27, and watchOS 27. If an application exploits this flaw, it can read personal information it should not be able to access, exposing users to privacy violations.
Affected Systems
All Apple platforms—iOS, iPadOS, macOS, tvOS, and watchOS—are affected when running versions earlier than 27. Devices that have not upgraded to the 27th release are vulnerable.
Risk and Exploitability
The EPSS score is less than 1%, indicating a very low probability of exploitation at present. The CVSS score is 5.5, giving a moderate severity level. The vulnerability is not listed in CISA’s KEV catalog. The primary risk is that an attacker who persuades a user to install a malicious third‑party application could read protected user data; the likelihood of such an event is inferred to be low based on the EPSS value, but the impact of a successful exploit would be significant.
OpenCVE Enrichment