Impact
Apple identified a path traversal issue that allowed applications to manipulate files that should have been guarded by the operating system. The flaw stems from insufficient validation of file path input, enabling an app to reference directories outside its intended scope. Unpatched to or overwrites critical system files, potentially leading to system instability or a break in security controls.
Affected Systems
The vulnerability affects Apple iOS and iPadOS versions prior to 26.7 and 27, as well as watchOS earlier than 27. The security update that mitigates the issue is included in iOS 26.7, iPadOS 26.7, iOS 27, iPadOS 27, and watchOS 27.
Risk and Exploitability
The EPSS score is less than 1%; the vulnerability is not listed in KEV and has a CVSS score of 5.5. An attacker would need to install or modify an app on the device to supply arbitrary file paths, and the path traversal flaw could allow the application to modify protected system files, potentially leading to system instability or security breaches.
OpenCVE Enrichment