Description
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5, watchOS 26.5. An app may be able to bypass certain Privacy preferences.
Published: 2026-05-11
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A permissions flaw in Apple operating systems allows any installed application to override user‑defined privacy settings and access personal data that the user intended to keep hidden. The vulnerability stems from insufficient enforcement of system restrictions on sensitive data access, and it compromises the confidentiality guarantees that devices are expected to provide. The issue was remedied by adding additional restrictions in version 26.5 of iOS, iPadOS, macOS, visionOS, and watchOS, after which the bypass can no longer be performed through a normal application.

Affected Systems

All Apple platforms that were running a release older than 26.5—iOS, iPadOS, macOS, visionOS, and watchOS—are affected. Once Apple rolled out the 26.5 update, the vulnerability was patched and the additional permission checks were enforced. Devices that are still on earlier releases remain at risk until they are upgraded.

Risk and Exploitability

The EPSS score of < 1 % and the fact that the vulnerability is not listed in the CISA KEV catalog indicate that public exploitation is currently unlikely. With a CVSS of 5.5 the flaw is classified as moderate severity; the primary risk is the ability to access or share private information beyond the user’s consent. Based on the description, it is inferred that the attack vector is app‑based—an attacker would need to either create a malicious application or compromise an existing one with elevated permissions to exploit the flaw. No additional conditions beyond the presence of such an application are stated, so the exploitation path is straightforward once the prerequisite is met.

Generated by OpenCVE AI on May 13, 2026 at 00:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade all Apple devices running iOS, iPadOS, macOS, visionOS, or watchOS to version 26.5 or later
  • Review and adjust app privacy permissions in Settings > Privacy, revoking any unnecessary access to sensitive data after updating
  • If managed via a mobile device management solution, enforce the latest OS version and restrict installation of unauthorised apps until updates are applied

Generated by OpenCVE AI on May 13, 2026 at 00:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 13 May 2026 01:00:00 +0000

Type Values Removed Values Added
Title Privacy Preference Bypass via Permissions Issue in Apple OS

Tue, 12 May 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 11 May 2026 23:00:00 +0000

Type Values Removed Values Added
Title Privacy Preference Bypass via Permissions Issue in Apple OS
Weaknesses CWE-284

Mon, 11 May 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple visionos
Apple watchos

Mon, 11 May 2026 20:45:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5, watchOS 26.5. An app may be able to bypass certain Privacy preferences.
References

Subscriptions

Apple Ios And Ipados Macos Visionos Watchos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-05-12T20:54:36.209Z

Reserved: 2026-03-03T16:36:03.994Z

Link: CVE-2026-28988

cve-icon Vulnrichment

Updated: 2026-05-12T20:54:28.116Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-05-11T21:18:58.820

Modified: 2026-05-12T22:16:33.140

Link: CVE-2026-28988

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-13T00:45:26Z

Weaknesses