Description
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access user-sensitive data.
Published: 2026-09-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Data Exposure
Action: Apply Patch
AI Analysis

Impact

A permissions flaw in Apple operating systems allows applications to bypass required checks and read user-sensitive data they should not access. The issue is a classic access‑control weakness (CWE‑284), resulting in confidentiality violations but does not grant code execution or other forms of privilege escalation.

Affected Systems

Apple devices running iOS, iPadOS, or macOS versions prior to the releases that incorporate the fix are vulnerable. The patch was applied in iOS 26.7, iOS 27, iPadOS 26.7, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7, so any device operating on an earlier version is at risk.

Risk and Exploitability

The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of exploitation. Based on the description, an attacker would need to install or modify an application on the device to exploit the missing permission checks. The attack vector is most likely local, requiring a malicious or compromised app, and no publicly documented exploits are cited in the provided references.

Generated by OpenCVE AI on September 20, 2026 at 21:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the device to the latest iOS, iPadOS, or macOS release that contains the fixed permission restrictions.
  • Review installed applications for excessive or unnecessary permissions, and uninstall or revoke those that are not essential.
  • If a system update cannot be applied immediately, limit or disable permissions for potentially affected applications through the system settings to reduce the risk of data exposure.

Generated by OpenCVE AI on September 20, 2026 at 21:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Title Permission Bypass Enabling Access to User Sensitive Data on Apple Devices

Thu, 17 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Wed, 16 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Title Permissions Issue Enabling Access to User‑Sensitive Data on Apple iOS, iPadOS, and macOS
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Title Permissions Issue Enabling Access to User‑Sensitive Data on Apple iOS, iPadOS, and macOS
Weaknesses CWE-284

Tue, 15 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Vendors & Products Apple
Apple ios And Ipados
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access user-sensitive data.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-16T12:22:35.317Z

Reserved: 2026-07-22T00:45:26.180Z

Link: CVE-2026-65345

cve-icon Vulnrichment

Updated: 2026-09-16T12:22:11.599Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:19.430

Modified: 2026-09-17T16:00:01.333

Link: CVE-2026-65345

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T21:45:04Z

Weaknesses