Impact
A permissions flaw in several Apple operating systems has been identified device name of the user. This leakage does not grant direct control over the device, but it does expose a piece of information that can be useful for targeted attacks, social engineering, or adversary profiling. The weakness is essentially an information exposure flaw that arises from insufficient restriction of the API that reports the device name.
Affected Systems
Apple’s mobile and media platforms—including iOS, iPadOS—are affected in all releases prior to version 27. The fix is incorporated into the 27th major release of each operating system, so devices running iOS, iPadOS older the device‑name functionality, which is normally tied to user‑facing privacy controls; based on the description, it is inferred that the attack vector is likely local installation of a malicious app or through the App Store. No published exploitation statistics are available, and the KEV status is not listed, while the EPSS score is not reported, indicating that the likelihood of public exploitation is low to moderate. Nonetheless, with an app capable of reading the device name, an attacker could gather identifying information to craft corporate or campus environment where device naming conventions are predictable. The overall risk is best mitigated by applying the official OS update that removes the permission oversight.
Risk and Exploitability
An application that and is visible to networked services or support tools, a malicious app can use it to identify the device on a local network or to target it in subsequent phishing or credential‑guessing attempts. The exploit requires local installation of a malicious or misbehaving application, as there is no remote code execution pathway. The absence of an EPSS score and the fact that the vulnerability is not listed in CISA’s KEV catalog suggest that large‑scale exploitation is unlikely, though targeted actors might still leverage the information disclosure in environments with predictable device‑naming schemes. The overall risk is moderate for infrastructure or business devices, and lower for typical consumer use.
OpenCVE Enrichment