Description
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to modify protected parts of the file system.
Published: 2026-09-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation via File System Modification
Action: Patch Now
AI Analysis

Impact

The reported vulnerability is a permissions flaw that permits an application to write to protected sections of the file system. This flaw can let a malicious or compromised app alter critical system or application files, potentially enabling privilege escalation and tampering with device configuration. The weakness is classified as CWE‑732, representing the inability to correctly enforce discretionary access controls.

Affected Systems

Apple iOS and iPadOS versions prior to 26.7 and 27, and Apple macOS releases before Golden Gate 27, Sequoia 15.8, and Tahoe 26.7 are affected. Devices running those OS versions are susceptible until the vulnerability is resolved through an update.

Risk and Exploitability

The EPSS score of less than 1% signals that exploitation is currently considered unlikely, and the vulnerability is not listed in CISA’s KEV catalog. The CVSS score of 5.5 indicates moderate impact. Based on the description, it is inferred that an attacker would need to install a malicious application on the device, making this a local or installation‑based attack vector. With no publicly available exploits, the risk largely lies in the potential impact should the flaw be abused by a privileged app. The mitigation is most effectively achieved by upgrading the operating system to a patched release.

Generated by OpenCVE AI on September 20, 2026 at 21:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update iOS to 26.7 or later, 27 or newer, or the corresponding iPadOS releases
  • Upgrade macOS to Golden Gate 27+, Sequoia 15.8+, or Tahoe 26.7+
  • Limit installation of third‑party applications and enforce the least privilege principle to reduce exposure
  • Monitor critical file system locations for unauthorized changes to detect potential abuse early
  • Review Apple’s support documentation for any additional runtime restrictions or security settings that can further harden the device

Generated by OpenCVE AI on September 20, 2026 at 21:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Title Permissions flaw allows modification of protected file system areas

Thu, 17 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Wed, 16 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-732
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title Permission Abuse Allowing Apps to Modify Protected File System
Weaknesses CWE-284

Tue, 15 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Title Permission Abuse Allowing Apps to Modify Protected File System
Weaknesses CWE-284

Tue, 15 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Vendors & Products Apple
Apple ios And Ipados
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to modify protected parts of the file system.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-16T14:32:25.539Z

Reserved: 2026-07-22T00:45:50.324Z

Link: CVE-2026-65348

cve-icon Vulnrichment

Updated: 2026-09-16T14:30:35.228Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:19.863

Modified: 2026-09-17T15:59:39.870

Link: CVE-2026-65348

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T22:00:09Z

Weaknesses
  • CWE-732

    Incorrect Permission Assignment for Critical Resource