Impact
A logic bug was identified in iOS and iPadOS that was addressed with additional checks in later releases. The issue allows an attacker who has physical access to a locked device to view sensitive user information. This vulnerability directly impacts the confidentiality of user data and can lead to a loss of privacy when an adversary is in physical proximity to the device.
Affected Systems
The vulnerability affects Apple iOS and iPadOS devices running versions older than iOS 26.7 and iPadOS 26.7, and older than iOS 27 and iPadOS 27. Any device before the 26.7/27 releases is considered affected; recent releases implement the corrective checks intended to prevent this oversight.
Risk and Exploitability
The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploitation. However, the attack requires only physical access to a locked device, which is a low‑barrier vector for motivated attackers. Because the flaw results in information disclosure, its potential impact on confidentiality is high. Until the device firmware is updated, an adversary with physical control can exploit this weak logic to read protected data. The fix is available in iOS 26.7/iPadOS 26.7 and iOS 27/iPadOS 27.
OpenCVE Enrichment