Description
An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3. An app may be able to access sensitive user data.
Published: 2026-02-11
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Sensitive Data Exposure
Action: Patch Now
AI Analysis

Impact

An authorization flaw in Apple iOS and iPadOS allows an application to access sensitive user data that it should not see. The bug results from incorrect state handling, which the OS fixes in newer releases. This flaw enables disclosure of personally identifiable information, compromising user confidentiality.

Affected Systems

Apple iOS and iPadOS. All device operating system builds older than iOS 18.7.5, iPadOS 18.7.5, iOS 26.3, and iPadOS 26.3 are vulnerable.

Risk and Exploitability

The publicly reported CVSS score is 5.5, indicating a moderate security impact. The EPSS score of less than 1% suggests a very low probability of exploitation at this time, and the vulnerability is not listed in CISA’s KEV catalog. The nature of the issue points to a local attack model where a malicious or compromised application could gain unauthorized data access, typically requiring the user to install or run the app. Until an OS update is applied, the affected systems remain at moderate risk of data exposure.

Generated by OpenCVE AI on April 15, 2026 at 20:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest iOS or iPadOS update (18.7.5 or 26.3) to patch the state management flaw.
  • Verify that installed applications do not request or read sensitive data beyond their intended purpose.
  • Continuously monitor application permissions and audit system logs for unexpected data access attempts.

Generated by OpenCVE AI on April 15, 2026 at 20:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Apr 2026 21:15:00 +0000

Type Values Removed Values Added
Title Authorization Issue Enabling Access to Sensitive User Data in iOS and iPadOS

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Description An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, iOS 18.7.5 and iPadOS 18.7.5. An app may be able to access sensitive user data. An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3. An app may be able to access sensitive user data.

Fri, 13 Feb 2026 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 12 Feb 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Thu, 12 Feb 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Vendors & Products Apple
Apple ios And Ipados

Wed, 11 Feb 2026 23:15:00 +0000

Type Values Removed Values Added
Description An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, iOS 18.7.5 and iPadOS 18.7.5. An app may be able to access sensitive user data.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:21:08.743Z

Reserved: 2025-11-11T14:43:07.872Z

Link: CVE-2026-20678

cve-icon Vulnrichment

Updated: 2026-02-13T18:09:54.415Z

cve-icon NVD

Status : Modified

Published: 2026-02-11T23:16:10.217

Modified: 2026-04-02T19:21:21.847

Link: CVE-2026-20678

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-15T21:00:09Z

Weaknesses