Impact
A local application may be able to read a persistent account identifier that is tied to the device. This constitutes a CWE-200 Information Exposure weakness that allows the app to disclose personal information that can be used to track or correlate user activity across services. The vulnerability does not enable code execution, privilege escalation, or denial-of-service, but it does compromise user confidentiality.
Affected Systems
Apple operating systems that run before the 27 releases—namely iOS, iPadOS, tvOS, visionOS, and watchOS—are affected. Each platform’s security state is fixed in the corresponding 27 version, eliminating the vulnerability from those updated releases.
Risk and Exploitability
The CVSS score of 7.5 classifies the issue as high severity. The EPSS score of less than 1% indicates a very low probability that the vulnerability will be actively exploited, and the CVE is not currently listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires the attacker to execute code locally on the target device, typically through a malicious application or compromised app. While public exploitation has not been documented, the confidentiality impact warrants prompt remediation.
OpenCVE Enrichment