Description
An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to access sensitive user data.
Published: 2026-07-27
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authorization flaw stemming from improper state management permits a malicious or compromised application to access sensitive user data. The vulnerability is resolved in all 26.6 releases of the Apple operating systems. If exploited, the flaw could allow the application to read or alter privileged data, thereby compromising the confidentiality and integrity of user information.

Affected Systems

The flaw impacts Apple platforms, including iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. All devices running a version prior to 26.6 are vulnerable, until the respective 26.6 updates are installed.

Risk and Exploitability

EPSS score is <1% and KEV is not listed, so the probability of current exploitation is low. The CVSS score of 6.5 indicates significant impact. The vulnerability involves unauthorized data access, indicating a high potential impact if an attacker can install or persuade a user to run a malicious application. The attack requires local or user‑trusted app execution; no remote exploit path is documented.

Generated by OpenCVE AI on August 3, 2026 at 16:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest 26.6 OS update on all affected Apple devices
  • Remove or restrict any untrusted applications that could exploit the flaw
  • Enforce least‑privilege permissions for app access to sensitive data and monitor for abnormal data access behavior

Generated by OpenCVE AI on August 3, 2026 at 16:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Title Authorization flaw exposing sensitive user data on Apple OS versions prior to 26.6

Sun, 02 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
Title Authorization Bypass Lets Apps Access Sensitive User Data via Improper State Management
Weaknesses CWE-284

Tue, 28 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Authorization Bypass Lets Apps Access Sensitive User Data via Improper State Management
Weaknesses CWE-284

Tue, 28 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to access sensitive user data.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T16:30:48.141Z

Reserved: 2026-07-20T18:10:18.985Z

Link: CVE-2026-64743

cve-icon Vulnrichment

Updated: 2026-07-28T16:25:13.125Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:17:13.187

Modified: 2026-07-29T19:52:00.697

Link: CVE-2026-64743

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T16:45:03Z

Weaknesses