Impact
An application can bypass entitlement checks in Apple Safari, iOS, iPadOS, macOS, and visionOS, allowing it to read or modify sensitive user data that should be protected. The flaw is an authorization weakness that grants unauthorized access to confidential information, potentially leading to data leakage or manipulation.
Affected Systems
The vulnerability affects any installed version of Safari, iOS, iPadOS, macOS, or visionOS that is earlier than the security updates. Unsigned or legacy releases of Safari before version 27, iOS and iPadOS before 26.7 or 27, macOS Golden Gate before 27, and visionOS before 27 remain vulnerable.
Risk and Exploitability
Based on the description, it is inferred that exploitation requires a local or malicious application that successfully evades the added entitlement checks. The CVSS score of 5.5 indicates moderate severity, and the EPSS score of less than 1 % suggests a very low likelihood of active exploitation. The vulnerability is not listed in the CISA KEV catalog, implying no widespread exploitation has been observed. The overall risk remains moderate with a low probability of an active attack at present.
OpenCVE Enrichment