Description
An access issue was addressed with improved access restrictions. This issue is fixed in Safari 26.6, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to read files outside of its sandbox.
Published: 2026-07-27
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The CVE describes an access issue where an application can read files outside its sandbox due to insufficient access restrictions. This flaw allows a malicious or compromised app to retrieve sensitive data that belongs to other apps or to the system, potentially exposing confidential information. Because the vulnerability arises from weak sandbox enforcement, it represents an information‑disclosure weakness.

Affected Systems

Affected Apple products include Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. Applications running on versions prior to Safari 26.6, iOS 18.7.10, iPadOS 18.7.10, iOS 26.6, iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6 are vulnerable. The patch in 26.6 and later addresses the issue for each platform.

Risk and Exploitability

The vulnerability is local, requiring an application already installed on the device to exploit it, and permits reading files outside the intended sandbox due to inadequate access restrictions. The CVSS score of 6.5 indicates medium severity. The EPSS score indicates a very low exploitation probability (< 1%) and the vulnerability is not listed in CISA’s KEV catalog, implying it has not yet been widely leveraged. Nonetheless, the ability to read data beyond the sandbox raises the risk of confidential data exposure, especially on shared devices or in enterprise environments. Mitigating this risk requires prompt application of the vendor‑issued updates.

Generated by OpenCVE AI on August 17, 2026 at 22:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Safari (26.6) and operating system updates for iOS, iPadOS, macOS, tvOS, visionOS, and watchOS.
  • Restart devices after updates to ensure sandbox controls are reinitialized.
  • Disable or remove any third‑party, legacy browsers or applications that run with outdated sandbox rules.

Generated by OpenCVE AI on August 17, 2026 at 22:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title App Access to Files Outside Sandbox in Apple Products

Mon, 17 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description An access issue was addressed with improved access restrictions. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to read files outside of its sandbox. An access issue was addressed with improved access restrictions. This issue is fixed in Safari 26.6, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to read files outside of its sandbox.
References

Wed, 05 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Apple Applications May Read Files Outside Sandbox

Wed, 29 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Apple Applications May Read Files Outside Sandbox
Weaknesses CWE-284

Tue, 28 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple safari
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple safari
Apple tvos
Apple visionos
Apple watchos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description An access issue was addressed with improved access restrictions. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to read files outside of its sandbox.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-08-17T21:30:28.963Z

Reserved: 2026-05-01T22:46:27.822Z

Link: CVE-2026-43821

cve-icon Vulnrichment

Updated: 2026-07-28T19:12:42.520Z

cve-icon NVD

Status : Modified

Published: 2026-07-27T21:17:05.010

Modified: 2026-08-17T22:17:13.787

Link: CVE-2026-43821

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T23:00:06Z

Weaknesses