Description
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to access sensitive user data.
Published: 2026-07-27
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A logic issue in macOS, iOS, and iPadOS internal checks allows an application to locate and read sensitive user data that should not be accessible. The flaw was identified and addressed by adding stricter validation, and the vulnerability is fixed in iOS 18.7.10, iPadOS 18.7.10, Sequoia 15.7.8, Sonoma 14.8.8, and Tahoe 26.6. Until the update is installed, a malicious or compromised app could read protected data. Based on the description, it is inferred that the flaw can be exploited by a local application without additional conditions.

Affected Systems

Affected are Apple macOS releases prior to the security patches: Sequoia 15.x, Sonoma 14.x, and Tahoe 26.x, as well as iOS and iPadOS versions earlier than 18.7.10. The issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, iOS 18.7.10, and iPadOS 18.7.10. Systems running earlier minor or patch versions of these major releases are considered vulnerable.

Risk and Exploitability

The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, suggesting that known exploitation activity is low. The flaw in macOS, iOS, and iPadOS can be leveraged by a malicious application or a local attacker to retrieve protected data. The likely attack vector is inferred to be a local application exploiting the logic flaw. The attack vector is most likely local; remote exploitation would require additional conditions that are not documented. While no active exploits are documented, the vulnerability represents a medium risk until mitigated. The CVSS score of 5.5 indicates medium severity, and this rating combined with the low EPSS confirms the moderate potential impact.

Generated by OpenCVE AI on August 18, 2026 at 01:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Apple OS update that contains the fix for the identified OS versions.
  • Tighten application permissions by reviewing and restricting entitlements, ensuring the application has only the minimum privileges needed (addressing CWE-284).
  • Enforce App Sandbox settings or app whitelisting to prevent unauthorized data access, and monitor system logs for suspicious data access attempts.

Generated by OpenCVE AI on August 18, 2026 at 01:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Title App Data Access Logic Flaw

Mon, 17 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to access sensitive user data. A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to access sensitive user data.
References

Mon, 03 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title Logic Issue Allowing App Access to Sensitive User Data on macOS

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Logic Issue Allowing App Access to Sensitive User Data on macOS
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to access sensitive user data.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-08-17T21:29:50.366Z

Reserved: 2026-07-20T18:09:47.192Z

Link: CVE-2026-64723

cve-icon Vulnrichment

Updated: 2026-07-28T15:02:04.284Z

cve-icon NVD

Status : Modified

Published: 2026-07-27T21:17:11.253

Modified: 2026-08-17T22:17:18.073

Link: CVE-2026-64723

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T01:30:05Z

Weaknesses