Description
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. A remote attacker may be able to bypass network filters.
Published: 2026-07-27
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An inconsistent user interface issue addressed with improved state management can allow a remote attacker to manipulate the device’s internal state, enabling them to bypass network filtering controls. This flaw is medium‑severity and could let malware or unauthorized traffic traverse a device’s network filters, potentially exposing sensitive data or allowing outbound connections that should be blocked.

Affected Systems

Apple devices running iOS 26.6 or earlier, iPadOS 26.6 or earlier, macOS Sequoia 15.7.8 or earlier, macOS Sonoma 14.8.8 or earlier, macOS Tahoe 26.6 or earlier, tvOS 26.6 or earlier, visionOS 26.6 or earlier, and watchOS 26.6 or earlier are affected as noted in the vendor’s advisories.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate risk, and the EPSS score of less than 1% shows that exploitation is currently rare. The vulnerability is not listed in the CISA KEV catalog, which suggests no known widespread exploitation. Nonetheless, a remote attacker can trigger the UI inconsistency to alter network filter state, so the risk remains significant enough to warrant timely remediation. No public exploit appears to be in circulation at the time of this assessment.

Generated by OpenCVE AI on August 17, 2026 at 23:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Apple operating system updates for all affected devices, which correct the flawed state‑management logic that can lead to network filter bypass.
  • If a patch cannot be applied immediately, isolate unpatched devices from the rest of the network and enforce stricter firewall rules to block traffic that could exploit the filter bypass, reducing the risk of unauthorized network access.
  • Monitor network logs for anomalous outbound connections originating from Apple devices, focusing on evidence of state manipulation that may expose sensitive data per CWE-451 and investigate any suspicious activity promptly.

Generated by OpenCVE AI on August 17, 2026 at 23:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title UI State Management Defect Enabling Network Filter Bypass

Mon, 17 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. A remote attacker may be able to bypass network filters. An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. A remote attacker may be able to bypass network filters.
References

Wed, 05 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Title UI State Management Defect Enabling Network Filter Bypass

Tue, 04 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Title Inconsistent UI State Management Allows Network Filter Bypass on Apple Devices
Weaknesses CWE-20
CWE-285

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Inconsistent UI State Management Allows Network Filter Bypass on Apple Devices
Weaknesses CWE-20
CWE-285
CWE-451
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. A remote attacker may be able to bypass network filters.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-08-17T21:29:43.566Z

Reserved: 2026-07-20T18:09:54.848Z

Link: CVE-2026-64735

cve-icon Vulnrichment

Updated: 2026-07-28T14:48:27.287Z

cve-icon NVD

Status : Modified

Published: 2026-07-27T21:17:12.463

Modified: 2026-08-17T22:17:19.020

Link: CVE-2026-64735

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T23:30:04Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information