Impact
The flaw allows interacting applications to circumvent the operating system’s privacy preferences, resulting in the disclosure of sensitive data that the system was designed to protect. The underlying weakness is an improper handling of privacy settings, consistent with improper disclosure of information (CWE‑200).
Affected Systems
Apple iOS and iPadOS versions earlier than 26.7 and 27, and visionOS earlier than 27 are affected. A vulnerability exists whenever an application can invoke the compromised API or service, allowing it to read data that the user had explicitly restricted through privacy settings.
Risk and Exploitability
The EPSS score is less than 1 % and the vulnerability is not listed in the CISA KEV catalog, and no publicly documented exploits currently exist. In practice, exploitation would require a malicious application running on the device or an attacker capable of delivering such an application, such as through an app store or supply‑chain compromise. Because the weakness directly discloses protected user data, the residual risk remains significant even in the absence of active exploitation evidence.
OpenCVE Enrichment