Impact
An application may delete credentials stored in Keychain because the vulnerable code that previously prevented this action was removed. The flaw is resolved in iOS 27, iPadOS 27, macOS Golden Gate 27 and visionOS 27. The vulnerability allows unauthorized removal of stored passwords and tokens, compromising the integrity of the credential store.
Affected Systems
Apple iOS, iPadOS, macOS and visionOS are affected. The flaw persists in any version prior to iOS 27, iPadOS 27, macOS Golden Gate 27, and visionOS 27. It has been fixed by removing the vulnerable code in those 27 releases.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating limited publicly known exploitation. The most likely attack vector is local, requiring a malicious application to be installed or executed on the device. An attacker could exploit the lack of proper authorization controls to delete Keychain items, potentially affecting all users of the device and leading to significant credential loss.
OpenCVE Enrichment