Executive brief
A security issue in Apple's mobile and wearable operating systems could allow a third-party application to improperly access camera metadata. In practice, this flaw could enable a malicious app to capture a user's screen without proper authorization. This could lead to the exposure of sensitive information displayed on the device, though it requires a user to have the malicious app installed and running.
Technical details
A logic issue existed in the way Apple operating systems managed application access to camera metadata. By exploiting this flaw, a locally installed malicious application could bypass intended restrictions to capture the device's screen. The vulnerability was addressed through improved logic and state management within the affected components. The issue affects multiple Apple platforms including iOS, iPadOS, and visionOS. Patches are available in iOS 18.7.9, iPadOS 18.7.9, iOS 26.5, iPadOS 26.5, and visionOS 26.5.
Affected products
- Apple iOS Before 18.7.9, before 26.5
- Apple iPadOS Before 18.7.9, before 26.5
- Apple visionOS Before 26.5
Timeline
- 2026-05-11: disclosed
- 2026-05-11: patched