Description
This issue was addressed with improved checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to access sensitive user data.
Published: 2026-07-27
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Apple operating systems lets an installed application read user data that it should not access. The vulnerability arises from insufficient authorization checks when accessing sensitive system information. This can lead to the disclosure of contacts, messages, or other personal data, compromising confidentiality. The weakness maps to CWE-200 (Information Exposure).

Affected Systems

Apple iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6 contain the fix. All versions older than those listed are vulnerable.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate impact, and the EPSS score of <1% implies a low likelihood of exploitation. The vulnerability is not listed in CISA KEV, and no public exploits are documented. Based on the description, it is inferred that the attack vector is local, requiring a malicious or poorly designed third‑party application to read protected data. The lack of a KEV listing and the low EPSS score reduce the urgency, but the potential to exfiltrate private data warrants timely patching.

Generated by OpenCVE AI on August 4, 2026 at 23:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Apple firmware updates for iOS, iPadOS, macOS, tvOS, visionOS, and watchOS that include the fix (e.g., iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, or watchOS 26.6).
  • Review installed apps and revoke or uninstall any that request unnecessary access to sensitive data; use the device’s privacy settings to restrict data access for apps that remain.
  • Keep the OS and applications updated and monitor Apple support for further advisories or workarounds.

Generated by OpenCVE AI on August 4, 2026 at 23:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Apple OS Local Application Data Disclosure via Improper Authorization Checks

Tue, 04 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Title Information Disclosure via Unrestricted Sensitive Data Access in Apple Operating Systems
Weaknesses CWE-284

Thu, 30 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Title Information Disclosure via Unrestricted Sensitive Data Access in Apple Operating Systems
Weaknesses CWE-284

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description This issue was addressed with improved checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to access sensitive user data.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T14:22:10.106Z

Reserved: 2026-05-01T22:46:27.820Z

Link: CVE-2026-43801

cve-icon Vulnrichment

Updated: 2026-07-28T14:21:58.099Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:17:03.337

Modified: 2026-07-28T18:58:29.487

Link: CVE-2026-43801

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T00:00:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor