Apple Keychain Data Backup Vulnerability Allowing Access to Sensitive Information

Vulnerability

A vulnerability exists in the handling of keychain data backups on iOS, iPadOS, and visionOS. This issue allows sensitive keychain information to be accessed from an iOS backup, potentially leading to unauthorized disclosure of personal data. The vulnerability arises from inadequate data access restrictions, which have been addressed in the latest versions of the operating systems.

Impact

Exploitation of this vulnerability could result in the unauthorized access and disclosure of sensitive keychain data, including passwords and other personal information, from an iOS backup.

Remediation

Users can update to iOS 18.4, iPadOS 18.4, or visionOS 2.4 to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
4.2
impact
2.5
exploitability
4.7
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.