Impact
Apple identified a path traversal issue that allowed applications to manipulate files that should have been guarded by the operating system. The flaw stems from insufficient validation of file path input, enabling an app to reference directories outside its intended scope. Unpatched to or overwrites critical system files, potentially leading to system instability or a break in security controls.
Affected Systems
The vulnerability affects Apple iOS and iPadOS versions prior to 26.7 and 27, as well as watchOS earlier than 27. The security update that mitigates the issue is included in iOS 26.7, iPadOS 26.7, iOS 27, iPadOS 27, and watchOS 27.
Risk and Exploitability
No EPSS score or KEV listing is available, and a CVSS score is not published. The application that is able to supply arbitrary file paths, and would require the attacker to be able to install or modify an app on the device. Because the flaw can affect system files, compromise could result in a local privilege escalation or system integrity violation if successfully exploited.
OpenCVE Enrichment