A vulnerability classified as critical has been found in joshuayoes ios-simulator-mcp up to 1.3.2. Affected is the function ui_tap. The manipulation leads to os command injection.

This vulnerability is traded as CVE-2025-52573. Local access is required to approach this attack. There is no exploit available.

It is recommended to upgrade the affected component.