Description
A logic issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. An app may be able to leak sensitive user information.
Published: 2026-08-17
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A logic flaw in the operating systems can be exploited by a third‑party application to access and disclose sensitive user information. The flaw involves missing or insufficient checks that allow the application to read data that it should not be able to view. The result is the potential disclosure of personal data, which could be used for identity theft or other malicious purposes.

Affected Systems

Apple iOS and iPadOS versions prior to 26.6.1 and macOS Tahoe prior to 26.6.2 contain the logic issue. The fix, introduced in iOS 26.6.1, iPadOS 26.6.1, and macOS Tahoe 26.6.2, adds improved checks to prevent the leak.

Risk and Exploitability

Because the EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog, the likelihood of active exploitation remains uncertain. The attack appears to require local execution by an installed application, indicating that a malicious or compromised app could trigger the data leak. No public exploitation evidence or known exploit code is documented in the provided information.

Generated by OpenCVE AI on August 17, 2026 at 23:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to iOS 26.6.1, iPadOS 26.6.1, or macOS Tahoe 26.6.2 or newer.
  • Restrict or remove third‑party applications that may read sensitive data by limiting permissions or uninstalling untrusted apps.
  • Monitor device logs and application behavior for signs of unauthorized data disclosure, especially from recently installed or updated apps.

Generated by OpenCVE AI on August 17, 2026 at 23:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Logic flaw in Apple OS allows app to leak sensitive user information
Weaknesses CWE-200

Mon, 17 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Vendors & Products Apple
Apple ios And Ipados
Apple macos

Mon, 17 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description A logic issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. An app may be able to leak sensitive user information.
References

Subscriptions

Apple Ios And Ipados Macos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-08-17T21:30:27.897Z

Reserved: 2026-07-22T00:45:26.179Z

Link: CVE-2026-65339

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-17T22:17:24.850

Modified: 2026-08-17T22:17:24.850

Link: CVE-2026-65339

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T00:00:05Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor