- Description
- This issue was addressed through improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6. An attacker with physical access may be able to access sensitive user data during iPhone Mirroring.
- Source
- product-security@apple.com
- NVD status
- Modified
- Products
- ipados, iphone_os
CVSS 3.1
- Type
- Secondary
- Base score
- 4.6
- Impact score
- 3.6
- Exploitability score
- 0.9
- Vector string
- CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity
- MEDIUM
- 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CWE-284
- Hype score
- Not currently trending
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
"matchCriteriaId": "AB0E13A1-17E9-4198-A359-304F8145F34F",
"versionEndExcluding": "26.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
"matchCriteriaId": "622D61A7-C893-4550-800A-8CEDE14F3033",
"versionEndExcluding": "26.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]