Apple iPadOS
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*
A clickjacking vulnerability has been identified in the TCC (Transparency, Consent, and Control) framework of Apple operating systems, including iOS 18, iPadOS 18, and macOS Sequoia 15. This vulnerability allows an application to trick users into granting access to their photos by manipulating the user interface. The issue arises from inadequate handling of out-of-process views, which could be exploited to bypass user consent for accessing the Photos Library.
Exploitation of this vulnerability could lead to unauthorized access to a user's photo library, allowing apps to view or potentially manipulate personal photos without consent.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.