Impact
ApermissionsissueinAppleoperatingsystemsallowsalocalapplicationtoreadapersistentaccountidentifier,revealinguserinformationthatshouldbeprotected.Theflawisbasedonsufficientauthorizationchecks,enablingtheapptoaccesedatabeyonditsintendedscope.Thevulnerabilityresultsintheinadvertentdisclosureofsensitivedatawithinthedevicelocalstorage.
Affected Systems
AppleiOS, iPadOS, macOS, tvOS, visionOS, and watchOS versions older than the fixed releases (iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Tahoe 26.7, tvOS 27, visionOS 27, or watchOS 27) are affected.
Risk and Exploitability
The vulnerability is exploitable locally by installing or running code with application privileges. The CVSS score is 3.3, indicating low severity. The EPSS score is less than 1%, indicating a very low probability of exploitation. The flaw is not listed in the CISA KEV catalog, further suggesting limited public exploitation. Local or in‑device execution is sufficient, but the practical risk remains moderate for users of unpatched systems.
OpenCVE Enrichment