Description
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27. A malicious app may be able to break out of its sandbox.
Published: 2026-09-14
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Sandbox Escape
Action: Apply Patch
AI Analysis

Impact

A permissions flaw removes critical restrictions allowing a malicious application to escape its sandbox, potentially granting unauthorized access to system resources and the ability to execute additional code. This type of vulnerability can lead to full compromise of the device, changing the confidentiality, integrity, and availability of data and services on the affected operating system. The issue is resolved in the upcoming releases.

Affected Systems

Apple iOS, iPadOS, and macOS are affected. Devices running any version prior to iOS 27, iPadOS 27, or macOS Golden Gate 27 may be vulnerable.

Risk and Exploitability

The exploit is likely to be possible via a malicious app installed on the device; it requires local installation and does not rely on external network vectors. The EPSS score is less than 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, a sandbox escape carries a high severity impact because it allows an attacker to gain unauthorized access to system resources and execute further code.

Generated by OpenCVE AI on September 20, 2026 at 19:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the device to iOS 27, iPadOS 27, or macOS Golden Gate 27 or later
  • Disable installation of applications from untrusted or third‑party sources until the patch is applied
  • Use a managed device solution to enforce OS version compliance and monitor for anomalous sandbox escape attempts

Generated by OpenCVE AI on September 20, 2026 at 19:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Title Permissions Issue Enabling Sandbox Escape in Apple iOS, iPadOS, and macOS

Fri, 18 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Title Permissions Issue Allowing Sandbox Escape on Apple Operating Systems
Weaknesses CWE-284

Tue, 15 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Title Permissions Issue Allowing Sandbox Escape on Apple Operating Systems
Weaknesses CWE-284

Tue, 15 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Vendors & Products Apple
Apple ios And Ipados
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27. A malicious app may be able to break out of its sandbox.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-17T14:49:39.241Z

Reserved: 2026-07-22T00:45:50.325Z

Link: CVE-2026-65354

cve-icon Vulnrichment

Updated: 2026-09-17T14:49:30.429Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:20.543

Modified: 2026-09-18T14:40:32.717

Link: CVE-2026-65354

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T19:45:02Z

Weaknesses
  • CWE-269

    Improper Privilege Management