Description
This issue was addressed through improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to access sensitive user data.
Published: 2026-07-27
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability stems from inadequate state information handling, enabling a malicious or poorly configured application to read internal state values it should not access. The affected operating systems can be patched through the updates listed, and until then, an app may access sensitive user data. The weakness is catalogued as improper resource handling (CWE‑664).

Affected Systems

Affected Apple operating systems are all versions before the stated security updates: iOS and iPadOS prior to 26.6, macOS Sequoia before 15.7.8, macOS Sonoma before 14.8.8, macOS Tahoe before 26.6, tvOS, visionOS and watchOS before 26.6. Devices running these operating systems are vulnerable regardless of device type.

Risk and Exploitability

The CVSS score of 5.5 reflect a moderate impact; the EPSS score of less than 1 % indicates a low likelihood of exploitation in the wild. However, any application that can be installed on the device could potentially exploit the flaw, so the risk to confidentiality remains significant. Based on the description, the likely attack vector involves delivery or execution of a malicious or improperly configured application, which is a realistic scenario in environments with weak app vetting or jailbroken devices. Because the vulnerability is not listed in the CISA KEV catalog, no widespread exploitation campaign has yet been reported.

Generated by OpenCVE AI on August 17, 2026 at 23:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest Apple OS releases that include the state‑management fix (iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6).
  • Remove or block any third‑party applications that access sensitive data without clear user justification, especially those not signed by Apple.
  • Restrict application permissions through the system’s privacy settings to limit access to sensitive personal information, granting only the permissions explicitly required.

Generated by OpenCVE AI on August 17, 2026 at 23:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title State Management Flaw Enabling App Access to Sensitive User Data

Mon, 17 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description This issue was addressed through improved state management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to access sensitive user data. This issue was addressed through improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to access sensitive user data.
References

Wed, 05 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
Title State Management Flaw Enabling App Access to Sensitive User Data

Wed, 05 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title App Access to Sensitive User Data via Improper State Management
Weaknesses CWE-284

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title App Access to Sensitive User Data via Improper State Management
Weaknesses CWE-284
CWE-664
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description This issue was addressed through improved state management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to access sensitive user data.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-08-17T21:31:34.804Z

Reserved: 2026-07-20T18:09:47.192Z

Link: CVE-2026-64721

cve-icon Vulnrichment

Updated: 2026-07-28T14:19:54.745Z

cve-icon NVD

Status : Modified

Published: 2026-07-27T21:17:11.053

Modified: 2026-08-17T22:17:17.767

Link: CVE-2026-64721

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T23:45:03Z

Weaknesses
  • CWE-664

    Improper Control of a Resource Through its Lifetime