Description
This issue was addressed with improved data protection. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, watchOS 27. An app may be able to access sensitive user data.
Published: 2026-09-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized disclosure of sensitive user data
Action: Update OS
AI Analysis

Impact

Based on the description, it is inferred that the vulnerability arises from a flaw in Apple’s operating‑system data‑protection mechanisms (CWE-200) that allows any installed application to read sensitive user data without proper authorization, leading to a privacy breach.

Affected Systems

Apple iOS 26.7 and 27, iPadOS 26.7 and 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, and watchOS 27 are impacted; the issue is fixed in the listed releases.

Risk and Exploitability

The CVSS score of 5.5 indicates medium severity for unauthorized disclosure of user data, while the EPSS score of < 1 % suggests a low probability of exploitation. The vulnerability is not listed in CISA KEV, meaning no publicly known exploitation tools have been documented. Based on the description, it is inferred that attackers may be able to access sensitive data without requiring elevated privileges or code execution, although the exact prerequisites are not fully detailed.

Generated by OpenCVE AI on September 20, 2026 at 19:00 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest operating‑system updates that contain the data‑protection fix
  • Configure device privacy settings to restrict or block app access to sensitive data
  • Review and uninstall applications that request unnecessary sensitive information

Generated by OpenCVE AI on September 20, 2026 at 19:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Title Apple OS Data Protection Flaw Allows Unprivileged App to Read Sensitive User Data

Thu, 17 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Title Apple OS Data Protection Flaw Allows Unprivileged App to Read Sensitive User Data

Wed, 16 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Title App Data Leakage via Improper Data Protection on Apple OS
Weaknesses CWE-264

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Tue, 15 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Title App Data Leakage via Improper Data Protection on Apple OS
Weaknesses CWE-200
CWE-264

Mon, 14 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple watchos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description This issue was addressed with improved data protection. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, watchOS 27. An app may be able to access sensitive user data.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-15T18:17:42.487Z

Reserved: 2026-05-01T22:46:21.640Z

Link: CVE-2026-43664

cve-icon Vulnrichment

Updated: 2026-09-15T18:17:35.368Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:06.770

Modified: 2026-09-15T20:20:00.050

Link: CVE-2026-43664

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T19:15:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor