Description
A path handling issue was addressed with improved validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access user-sensitive data.
Published: 2026-09-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Access
Action: Update OS
AI Analysis

Impact

A path handling issue, addressed via improved validation, may allow an application to access files beyond intended directories. This flaw can lead to the disclosure of user‑sensitive data. The weakness is a classic path traversal vulnerability, categorized as CWE‑22.

Affected Systems

Affecting Apple iOS and iPadOS releases prior to version 27, Apple macOS releases before Golden Gate 27, Sequoia 15.8, or Tahoe 26.7. Users of these older operating systems are potentially exposed. The defect has been corrected in the listed later releases.

Risk and Exploitability

The CVSS score is 5.5. The EPSS score is approximately 0.18%, indicating a very low probability of exploitation. The KEV status is not listed, so no documented exploitation is known. Based on the description, the likely attack vector is local or controlled use of an application that handles arbitrary file paths. The flaw could allow a privilege‑constrained attacker to read files beyond intended directories by manipulating path inputs, potentially exposing user‑sensitive data.

Generated by OpenCVE AI on September 20, 2026 at 18:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest iOS, iPadOS, and macOS versions that include the fix (iOS 27, iPadOS 27, macOS Golden Gate 27 or later, macOS Sequoia 15.8 or later, macOS Tahoe 26.7 or later).
  • Ensure applications that handle path names are sandboxed or run with least privilege and validate input paths to allow only intended directories.
  • If upgrading is not possible, restrict use of applications that manipulate file paths from untrusted sources and consider disabling custom path‑handling features.

Generated by OpenCVE AI on September 20, 2026 at 18:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Title Path traversal vulnerability enabling unauthorized access to user data on Apple iOS and macOS

Thu, 17 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Title Path traversal vulnerability enabling unauthorized access to user data on Apple iOS and macOS

Wed, 16 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Wed, 16 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Title Path Traversal Vulnerability Allowing Unauthorized File Access in Apple Operating Systems

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Title Path Traversal Vulnerability Allowing Unauthorized File Access in Apple Operating Systems
Weaknesses CWE-22

Tue, 15 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Vendors & Products Apple
Apple ios And Ipados
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A path handling issue was addressed with improved validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access user-sensitive data.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-15T18:00:18.550Z

Reserved: 2026-07-20T18:10:30.632Z

Link: CVE-2026-64756

cve-icon Vulnrichment

Updated: 2026-09-15T18:00:06.535Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:14.990

Modified: 2026-09-16T17:27:38.007

Link: CVE-2026-64756

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T18:45:02Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')