Description
An authentication issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27. An app may be able to use the Sign In With Apple authentication flow to access the user's Apple Account.
Published: 2026-09-14
Score: n/a
EPSS: n/a
KEV: No
Impact: Authentication bypass allowing unauthorized access to Apple accounts
Action: Patch immediately
AI Analysis

Impact

This vulnerability involves improper state management in the Sign In With Apple authentication flow. An application could exploit this flaw to obtain authentication credentials and access a user's Apple Account without proper authorization. The weakness could allow an attacker to impersonate the user or gain unauthorized access to sensitive services tied to the Apple Account.

Affected Systems

Apple iOS and iPadOS running versions prior to 27; macOS versions prior to Golden Gate 27, Sequoia 15.8, or Tahoe 26.7; and visionOS versions prior to 27.

Risk and Exploitability

The CVE does not publish a CVSS score, and EPSS is unavailable. The vulnerability is not listed in the CISA KEV catalog, indicating no confirmed widespread exploitation at present. Nonetheless, because the flaw permits unauthorized access to user accounts via a widely used authentication mechanism, the potential impact for any affected device is significant. Attackers could abuse the Sign In With Apple flow to bypass expected state checks, a scenario that could be relatively straightforward once the flaw is known. The lack of known exploits does not diminish the risk that an attacker could develop a custom exploit targeting this state management issue.

Generated by OpenCVE AI on September 15, 2026 at 10:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade iOS, iPadOS, macOS, or visionOS to the patched versions (iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, or visionOS 27).
  • If an immediate OS upgrade is not possible, restrict the use of Sign In With Apple in applications until the official patch is applied.
  • Maintain awareness of Apple support advisories and apply future updates promptly.

Generated by OpenCVE AI on September 15, 2026 at 10:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Title Improper Authentication via Sign In With Apple State Management Issue
Weaknesses CWE-287

Mon, 14 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple visionos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple visionos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description An authentication issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27. An app may be able to use the Sign In With Apple authentication flow to access the user's Apple Account.
References

Subscriptions

Apple Ios And Ipados Macos Visionos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-14T20:49:06.881Z

Reserved: 2025-11-11T14:43:07.873Z

Link: CVE-2026-20683

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-14T21:17:04.900

Modified: 2026-09-14T21:17:04.900

Link: CVE-2026-20683

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T10:15:17Z

Weaknesses