Description
The issue was addressed with improved checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6. An app may be able to access user-sensitive data.
Published: 2026-09-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Data Exposure
Action: Update OS
AI Analysis

Impact

A weakness in how Apple operating systems verify application permissions allows a locally‑installed application to bypass normal access controls and read user‑sensitive data that it should not be able to access. The flaw is identified as an access control vulnerability, meaning an attacker can obtain confidential information through an unauthorized app.

Affected Systems

Apple iOS, iPadOS, macOS Tahoe, and visionOS versions earlier than 26.6 are affected. Devices running any of these operating systems at a vulnerable version can be compromised by installing an app that takes advantage of the improper checks.

Risk and Exploitability

The EPSS score is less than 1%, and the CVSS score is 5.5, indicating a moderate severity. The vulnerability is not listed in CISA KEV, so there are no known in‑the‑wild exploits. Likely attack vectors involve local installation or sideloading of applications that can read protected data. The confidentiality impact is significant, but the overall risk is mitigated by the low exploitation likelihood and the requirement that the device run a vulnerable OS version.

Generated by OpenCVE AI on September 20, 2026 at 21:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest OS updates: install iOS 26.6, iPadOS 26.6, macOS Tahoe 26.6, or visionOS 26.6, or newer.
  • Avoid installing non‑Apple or sideloaded applications and limit app permissions by disabling unnecessary sensitive permissions in Settings → Privacy.
  • Monitor Apple support and advisories for additional updates or guidance.

Generated by OpenCVE AI on September 20, 2026 at 21:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Wed, 16 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Access to User Sensitive Data via Improper Checks
Weaknesses CWE-284

Tue, 15 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Access to User Sensitive Data via Improper Checks
Weaknesses CWE-284

Tue, 15 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple visionos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple visionos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6. An app may be able to access user-sensitive data.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos Visionos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-16T12:24:25.712Z

Reserved: 2026-05-01T22:46:27.817Z

Link: CVE-2026-43762

cve-icon Vulnrichment

Updated: 2026-09-16T12:24:11.886Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:10.790

Modified: 2026-09-17T16:01:20.253

Link: CVE-2026-43762

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T22:00:09Z

Weaknesses