Description
An authentication issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27. An app may be able to use the Sign In With Apple authentication flow to access the user's Apple Account.
Published: 2026-09-14
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Authentication bypass allowing unauthorized access to Apple accounts
Action: Patch immediately
AI Analysis

Impact

This vulnerability involves improper flow. An application could exploit this flaw to obtain authentication credentials and access a user's Apple Account without proper authorization. The weakness could allow an attacker to impersonate the user or gain unauthorized access to sensitive services tied to the Apple Account.

Affected Systems

Apple iOS and iPadOS running versions earlier than 27; macOS versions earlier than Golden Gate 27, Sequoia 15.8, or Tahoe 26.7; and visionOS versions earlier than 27.

Risk and Exploitability

The EPSS score of less than 1% signals a very low likelihood of exploitation. A CVSS score of 7.1 indicates a high severity for authentication bypass. This vulnerability is not listed in the CISA KEV catalog, aligning with the low exploitation probability. While the flaw permits bypass of authentication checks during the Sign In With Apple flow, it could allow an attacker to gain unauthorized access to Apple accounts on affected devices. The risk remains limited by the low exploitation probability but remains significant if an attacker decides to target the specific state‑management flaw.

Generated by OpenCVE AI on September 20, 2026 at 20:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade iOS, iPadOS, macOS, or visionOS to the patched versions (iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, or visionOS 27).
  • If an immediate OS upgrade is not possible, applications should apply the official advisories and update promptly.
  • Monitor Apple Accounts for any sign of unauthorized access or anomalous activity, and investigate promptly if such activity is detected.

Generated by OpenCVE AI on September 20, 2026 at 20:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Title Authentication Bypass via Sign In With Apple Flow

Thu, 17 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Title Improper Authentication via Sign In With Apple State Management Issue
Weaknesses CWE-287

Tue, 15 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Title Improper Authentication via Sign In With Apple State Management Issue
Weaknesses CWE-287

Mon, 14 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple visionos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple visionos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description An authentication issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27. An app may be able to use the Sign In With Apple authentication flow to access the user's Apple Account.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos Visionos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-16T19:30:45.016Z

Reserved: 2025-11-11T14:43:07.873Z

Link: CVE-2026-20683

cve-icon Vulnrichment

Updated: 2026-09-16T19:29:57.398Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:04.900

Modified: 2026-09-17T14:26:22.617

Link: CVE-2026-20683

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T20:15:04Z

Weaknesses