Description
An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.6 and iPadOS 26.6. An app may be able to access sensitive user data.
Published: 2026-07-27
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authorization flaw in Apple iOS and iPadOS stems from improper state management. This vulnerability permits an application to read or manipulate sensitive user data that it should not be able to access, exposing personal or confidential information. The impact is the potential loss of data confidentiality and privacy, without requiring elevated privileges beyond using a malicious or compromised application.

Affected Systems

Apple iOS and iPadOS devices running any version earlier than 26.6 are impacted. The issue is fixed in iOS 26.6 and iPadOS 26.6 and does not affect later releases.

Risk and Exploitability

The EPSS score is < 1%, indicating a very low but non-zero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 5.5 reflects moderate severity. An attacker does not need special privileges beyond installing or running a malicious app, a likely attack vector inferred from the description. The flaw operates locally on the device, so any user who runs a malicious application could potentially exploit it. The moderate CVSS score combined with the low EPSS suggests that while exploitation is technically feasible, it is not widely observed at present.

Generated by OpenCVE AI on August 4, 2026 at 13:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the device to iOS 26.6 or iPadOS 26.6, which resolves the state‑management flaw.
  • Remove or restrict apps that may have been compromised or that request excessive sensitive permissions.
  • Monitor device logs and activity for signs of unauthorized data access and investigate any anomalies.

Generated by OpenCVE AI on August 4, 2026 at 13:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Tue, 04 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Title Authorization flaw allowing apps to read sensitive user data in iOS and iPadOS

Sun, 02 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
Title Apple iOS/iPadOS State Management Authorization Flaw Exposing Sensitive Data
Weaknesses CWE-284

Thu, 30 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Title Apple iOS/iPadOS State Management Authorization Flaw Exposing Sensitive Data
Weaknesses CWE-284

Tue, 28 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Vendors & Products Apple
Apple ios And Ipados

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.6 and iPadOS 26.6. An app may be able to access sensitive user data.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T17:56:01.516Z

Reserved: 2026-07-20T18:10:30.632Z

Link: CVE-2026-64755

cve-icon Vulnrichment

Updated: 2026-07-28T17:54:06.487Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:17:14.020

Modified: 2026-07-29T19:50:20.133

Link: CVE-2026-64755

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T13:45:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor