Impact
A permissions issue that allowed an application to access sensitive user data was present in earlier versions of several Apple operating systems. The issue was resolved by adding extra restrictions in the 27th release for iOS, iPadOS, macOS, tvOS, and watchOS. This flaw could let an app read or collect data that it should not have been able to access, potentially exposing personal information to malicious actors.
Affected Systems
Apple iOS, iPadOS, macOS, tvOS, and watchOS are affected. Devices running versions prior to the 27th release are vulnerable, as the fix was only introduced in those later releases.
Risk and Exploitability
The vulnerability is a classic improper access control problem that could be exploited by any third‑party application with elevated permissions. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog, but the potential for data exposure and the lack of a public exploit imply a moderate to high risk. An attacker would need to convince the user to install a malicious or compromised application, which could then read protected data.
OpenCVE Enrichment