Description
An authorization issue was addressed with improved validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. An app may be able to add contacts without user authorization.
Published: 2026-07-27
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authorization issue in Apple operating systems permitted an application to add contact records without user consent. The flaw was fixed in iOS 26.6, iPadOS 26.6, macOS (Tahoe) 26.6, visionOS 26.6, and watchOS 26.6. An attacker could maliciously populate a device's address book, potentially exposing private data or facilitating other targeted attacks.

Affected Systems

Apple iOS, iPadOS, macOS (Tahoe), visionOS, and watchOS are affected. The vulnerability exists in all releases released before version 26.6 of each OS.

Risk and Exploitability

EPSS data is available and indicates a < 1% exploitation probability. The CVSS score of 9.8 reflects a critical severity with remote impact. The flaw was not listed in CISA KEV. The likely attack vector is an application running on the device with app‑level privileges, potentially able to add contact records without user consent. With no publicly available exploit, the risk remains moderate because local application access is required, but the impact could be significant by corrupting the device's address book.

Generated by OpenCVE AI on August 4, 2026 at 23:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install all available updates for iOS, iPadOS, macOS, visionOS and watchOS to at least version 26.6.
  • After updating, review app permissions and revoke any third‑party app that has the ability to add contacts without explicit consent.
  • Periodically review system logs or contact management events to detect any unexpected contact additions.

Generated by OpenCVE AI on August 4, 2026 at 23:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Contact Creation via Authorization Bypass

Mon, 03 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Contact Creation Without User Authorization
Weaknesses CWE-284
CWE-285

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Contact Creation Without User Authorization
Weaknesses CWE-284
CWE-285
CWE-862
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple visionos
Apple watchos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description An authorization issue was addressed with improved validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. An app may be able to add contacts without user authorization.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos Visionos Watchos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T15:55:13.450Z

Reserved: 2026-07-20T18:10:18.985Z

Link: CVE-2026-64746

cve-icon Vulnrichment

Updated: 2026-07-28T15:55:09.501Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:17:13.487

Modified: 2026-07-28T18:43:51.407

Link: CVE-2026-64746

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T23:45:02Z

Weaknesses