Description
This issue was addressed with improved checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27, watchOS 27. An app may be able to access sensitive user data.
Published: 2026-09-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Data Exposure
Action: Patch OS
AI Analysis

Impact

Missing privilege checks in Apple operating systems allow an application to read or write sensitive user data that it should not access. The flaw is a failure to enforce application-level permissions, resulting in a confidential data breach that could expose personal communications, device settings, and other private information. The weakness is characterized as a missing authorization check (CWE‑284).

Affected Systems

Vulnerable Apple devices include iOS, iPadOS, macOS, visionOS, and watchOS running versions earlier than iOS 26.7, iPadOS 26.7, macOS Golden Gate 27, Sequoia 15.8, Tahoe 26.7, visionOS 27, and watchOS 27. Any device running a version earlier than these could potentially be compromised by a malicious or overly privileged app.

Risk and Exploitability

The CVSS score of 5.5 denotes moderate severity, while the EPSS score of less than 1 % and the absence from CISA’s KEV catalog suggest a low likelihood of real‑world exploitation. The most probable attack vector involves a user installing an app with unverified privileges or an app that falsely requests elevated access. The impact is confidential data loss, but there is little evidence of broader system compromise.

Generated by OpenCVE AI on September 20, 2026 at 19:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to the latest Apple OS releases that include the fix (iOS 26.7 or newer, iPadOS 26.7 or newer, macOS Golden Gate 27 or newer, Sequoia 15.8 or newer, Tahoe 26.7 or newer, visionOS 27 or newer, watchOS 27 or newer).
  • Verify app permissions before installation, avoid granting unnecessary data access, and remove apps that request excessive privileges.
  • Enable automatic updates on all Apple devices to ensure timely reception of future patches.

Generated by OpenCVE AI on September 20, 2026 at 19:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Title Apple OS Sensitive Data Exposure via Improper Privilege Verification

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Title Improper Check Allowing Apps to Access Sensitive User Data
Weaknesses CWE-200
CWE-285

Tue, 15 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Title Improper Check Allowing Apps to Access Sensitive User Data
Weaknesses CWE-200
CWE-285

Tue, 15 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple visionos
Apple watchos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description This issue was addressed with improved checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27, watchOS 27. An app may be able to access sensitive user data.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos Visionos Watchos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-17T16:52:26.008Z

Reserved: 2026-07-22T00:46:56.740Z

Link: CVE-2026-65403

cve-icon Vulnrichment

Updated: 2026-09-17T16:52:15.794Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:23.867

Modified: 2026-09-18T17:34:27.507

Link: CVE-2026-65403

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T20:00:04Z

Weaknesses