Description
A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, visionOS 27. An app may be able to modify protected parts of the file system.
Published: 2026-09-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Modification of protected filesystem regions
Action: Patch Immediately
AI Analysis

Impact

A path handling flaw allows an application to write to protected areas of the device’s filesystem, enabling an attacker to overwrite system files or directories. The vulnerability arises from insufficient validation of the path component during file resolution, which permits the creation of paths that traverse into privileged directories. Because the attacker can modify critical files, the flaw could compromise system integrity and potentially lead to further privilege escalation or denial of service.

Affected Systems

Apple iOS and iPadOS on versions earlier than 26.7 and 27, and visionOS on versions earlier than 27, are affected. The issue is fixed in iOS 26.7 and 27, iPadOS 26.7 and 27, and visionOS 27.

Risk and Exploitability

The flaw is local; it requires the execution of an unsanctioned application on the device, which is a realistic attack vector for malicious or compromised third‑party apps. The CVSS score of 5.5 indicates medium severity, and the EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. However, if exploitation occurs, the ability to modify protected filesystem locations presents a significant integrity impact and the potential for downstream privilege escalation.

Generated by OpenCVE AI on September 20, 2026 at 21:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the device firmware to iOS 26.7 or later, iPadOS 26.7 or later, or visionOS 27 or later.
  • Uninstall or disable any third‑party applications that are not from trusted sources and may attempt to write to protected filesystem locations.
  • Ensure the device remains in a non‑jailbroken state and consider using system integrity‑check tools to detect unauthorized file modifications.

Generated by OpenCVE AI on September 20, 2026 at 21:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Title Improper Path Validation Enabling Modification of Protected Filesystems

Wed, 16 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Wed, 16 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Title Path Handling Vulnerability Allowing Modification of Protected Filesystem Regions
Weaknesses CWE-20
CWE-40

Tue, 15 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Title Path Handling Vulnerability Allowing Modification of Protected Filesystem Regions
Weaknesses CWE-20
CWE-40

Tue, 15 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple visionos
Vendors & Products Apple
Apple ios And Ipados
Apple visionos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, visionOS 27. An app may be able to modify protected parts of the file system.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Visionos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-16T13:06:17.439Z

Reserved: 2026-07-22T00:47:18.621Z

Link: CVE-2026-65411

cve-icon Vulnrichment

Updated: 2026-09-16T13:04:15.488Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:24.743

Modified: 2026-09-16T15:25:36.677

Link: CVE-2026-65411

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T22:00:09Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')