Apple TCC Clickjacking Vulnerability Allowing Unauthorized Access to Photos

Vulnerability

A clickjacking vulnerability has been identified in the TCC (Transparency, Consent, and Control) framework of Apple operating systems, including iOS 18, iPadOS 18, and macOS Sequoia 15. This vulnerability allows an application to trick users into granting access to their photos by manipulating the user interface. The issue arises from inadequate handling of out-of-process views, which could be exploited to bypass user consent for accessing the Photos Library.

Impact

Exploitation of this vulnerability could lead to unauthorized access to a user's photo library, allowing apps to view or potentially manipulate personal photos without consent.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
2.5
exploitability
4.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.