Description
A logic issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. An app may be able to leak sensitive user information.
Published: 2026-08-17
Score: 5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive data leakage
Action: Patch
AI Analysis

Impact

A logic flaw in Apple’s operating systems allows an application to potentially read and disclose sensitive user data because of missing validation checks. The flaw is a failure of the system protection mechanism, identified as CWE‑693, which can compromise confidentiality. The issue is resolved in specific updates but remains exploitable on devices that have not installed them.

Affected Systems

Affected systems include Apple iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8 and macOS Tahoe 26.6.2, as well as tvOS 27, visionOS 27, and watchOS 27. Devices running earlier versions before these releases are vulnerable. All relevant Apple platforms are enumerated in the CNA vendor‑product list.

Risk and Exploitability

The CVSS base score of 5 indicates moderate severity, while the EPSS score of less than 1% and absence from CISA’s KEV catalog suggest a low likelihood of active exploitation. No publicly available exploit or evidence of ongoing attacks is documented, and the attack vector is not specified in the advisory, so the vulnerability may require local or privileged access to a target device. The risk to user privacy remains until devices are updated.

Generated by OpenCVE AI on September 21, 2026 at 07:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install iOS 26.6.1, iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, or watchOS 27 to fix the logic flaw.
  • Restrict or remove third‑party applications that may read sensitive data by limiting permissions or uninstalling untrusted apps.
  • Monitor device logs and application behavior for signs of unauthorized data disclosure, especially from recently installed or updated apps.

Generated by OpenCVE AI on September 21, 2026 at 07:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Title Logic Issue Potentially Exposing Sensitive Data in Apple iOS, iPadOS, and macOS

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A logic issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. An app may be able to leak sensitive user information. A logic issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. An app may be able to leak sensitive user information.
References

Tue, 18 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Title Logic Issue Potentially Exposing Sensitive Data in Apple iOS, iPadOS, and macOS

Tue, 18 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Tue, 18 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Title Logic flaw in Apple OS allows app to leak sensitive user information
Weaknesses CWE-200

Tue, 18 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Logic flaw in Apple OS allows app to leak sensitive user information
Weaknesses CWE-200

Mon, 17 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Vendors & Products Apple
Apple ios And Ipados
Apple macos

Mon, 17 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description A logic issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. An app may be able to leak sensitive user information.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-14T20:49:26.281Z

Reserved: 2026-07-22T00:45:26.179Z

Link: CVE-2026-65339

cve-icon Vulnrichment

Updated: 2026-08-18T13:28:07.396Z

cve-icon NVD

Status : Modified

Published: 2026-08-17T22:17:24.850

Modified: 2026-09-14T21:17:18.540

Link: CVE-2026-65339

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T07:15:07Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure