Impact
A flaw allows an application to delete items from the device Keychain because the operating system failed to enforce proper authorization checks. The vulnerability could be exploited to erase stored passwords and tokens, thereby compromising credential integrity and potentially disrupting authentication for all applications on the affected Apple platforms. This weakness is classified as CWE‑284, improper authorization.
Affected Systems
Apple iOS, iPadOS, macOS and visionOS running releases prior to iOS 27, iPadOS 27, macOS Golden Gate 27 and visionOS 27 are affected. The fix was delivered by removing the vulnerable code path in the 27 releases.
Risk and Exploitability
The CVSS score of 5.5 denotes moderate severity, and the EPSS score of less than 1% indicates a low probability of public exploitation. The vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is local; an attacker requires a malicious application to be installed or executed on the device, after which the app can delete Keychain items under the victim’s user account, leading to credential loss and potential service disruption.
OpenCVE Enrichment