Description
A logic issue was addressed with improved validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27. An app may be able to access sensitive user data.
Published: 2026-09-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Potential unauthorized access to sensitive user data
Action: Patch Now
AI Analysis

Impact

A logic flaw in Apple’s operating systems permits an application to retrieve sensitive user information. The issue stemmed from insufficient validation, a weakness commonly associated with CWE‑693. The flaw could result in confidentiality compromise if exploited by a malicious or poorly designed app.

Affected Systems

Apple devices running iOS 26.7 or earlier, iPadOS 26.7 or earlier, macOS Golden Gate 27 or earlier, macOS Sequoia 15.8 or earlier, macOS Tahoe 26.7 or earlier, tvOS 27 or earlier, and visionOS 27 or earlier are affected. Updated releases beginning with the listed versions contain the fix.

Risk and Exploitability

The vulnerability is not yet cataloged by CISA as a known exploited vulnerability, but the EPSS score indicates a less than 1% probability of exploitation. Consequently, the likelihood of exploitation is low. The CVSS score of 5.5 indicates moderate severity. The flaw can likely be triggered by any app installed on the device that is able to run with user context; precise attack vector details are not disclosed in the advisory.

Generated by OpenCVE AI on September 20, 2026 at 23:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update iOS to 26.7 or later, or iPadOS to 26.7 or later; install macOS Sequoia 15.8 or later, macOS Golden Gate 27 or later, macOS Tahoe 26.7 or later, or tvOS 27 or later, and visionOS 27 or later.
  • On devices that cannot be updated immediately, restrict the permissions granted to potentially risky applications or disable access to sensitive data via System Preferences.
  • Continuously monitor Apple support documentation for additional advisories and apply future updates as soon as they become available.

Generated by OpenCVE AI on September 20, 2026 at 23:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Title Logic Validation Issue Allowing Sensitive Data Access in Apple OSes

Sun, 20 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Title Logic flaw potentially exposing sensitive user data on Apple devices
Weaknesses CWE-20

Wed, 16 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Wed, 16 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title Logic flaw potentially exposing sensitive user data on Apple devices
Weaknesses CWE-20

Tue, 15 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A logic issue was addressed with improved validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27. An app may be able to access sensitive user data.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-16T12:44:50.430Z

Reserved: 2026-07-22T00:47:18.620Z

Link: CVE-2026-65406

cve-icon Vulnrichment

Updated: 2026-09-16T12:44:26.466Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:24.197

Modified: 2026-09-16T18:26:37.867

Link: CVE-2026-65406

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T23:45:06Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure