Description
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27. A malicious app may be able to break out of its sandbox.
Published: 2026-09-14
Score: n/a
EPSS: n/a
KEV: No
Impact: Sandbox Escape
Action: Apply Patch
AI Analysis

Impact

A permissions flaw removes critical restrictions allowing a malicious application to escape its sandbox, potentially granting unauthorized access to system resources, sensitive data, and the ability to execute additional code. This type of vulnerability can lead to full compromise of the device, changing the confidentiality, integrity, and availability of data and services on the affected operating system. The description indicates the issue is resolved in the upcoming releases.

Affected Systems

Apple iOS, iPadOS, and macOS are affected. Devices running any version prior to iOS 27, iPadOS 27, or macOS Golden Gate 27 may be vulnerable. The vendor has platform.

Risk and Exploitability

The exploit is likely to be possible via a malicious app installed on the device; it requires local installation and does not rely on external network vectors. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, but the impact of a sandbox escape justifies a high severity rating. Apple has mitigated the risk by enforcing the fix in the upcoming OS releases.

Generated by OpenCVE AI on September 15, 2026 at 09:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the device to iOS 27, iPadOS 27, or macOS Golden Gate 27 or later
  • Disable installation of applications from untrusted or third‑party sources until the patch is applied
  • Use a managed device solution to enforce OS version compliance and monitor for anomalous sandbox escape attempts

Generated by OpenCVE AI on September 15, 2026 at 09:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Title Permissions Issue Allowing Sandbox Escape on Apple Operating Systems
Weaknesses CWE-284

Tue, 15 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Vendors & Products Apple
Apple ios And Ipados
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27. A malicious app may be able to break out of its sandbox.
References

Subscriptions

Apple Ios And Ipados Macos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-14T20:49:39.505Z

Reserved: 2026-07-22T00:45:50.325Z

Link: CVE-2026-65354

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-14T21:17:20.543

Modified: 2026-09-14T21:17:20.543

Link: CVE-2026-65354

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T09:45:17Z

Weaknesses