Description
A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, visionOS 27. An app may be able to modify protected parts of the file system.
Published: 2026-09-14
Score: n/a
EPSS: n/a
KEV: No
Impact: Modification of protected filesystem for privileged operations
Action: Patch Immediately
AI Analysis

Impact

A path handling flaw can allow an application to write to protected areas of the device’s filesystem. The flaw arises from insufficient input validation during file path resolution, permitting unauthorized modification of sensitive files or directories. Because the affected components are protected by the operating system, an attacker can alter system data, potentially compromising integrity and leading to further privilege escalation. The description explicitly notes the potential for apps to modify protected parts of the file system.

Affected Systems

Apple’s mobile and desktop operating systems, including iOS and iPadOS on versions prior to 26.7 and 27, and visionOS prior to 27, are affected. The issue is patched in iOS 26.7 and 27, iPadOS 26.7 and 27, and visionOS 27.

Risk and Exploitability

The vulnerability is local in nature; it requires an app to be run on the device, which is a reasonable attack vector for malicious or compromised applications distributed through the App Store or other channels. The EPSS score is not available, but the lack of a KEV listing does not diminish the potential impact, as the flaw still allows modification of protected filesystem areas. The absence of a specific CVSS score precludes a precise severity rating, yet the described capability of altering system files indicates high potential damage for confidentiality, integrity, and availability.

Generated by OpenCVE AI on September 15, 2026 at 10:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the device to iOS 26.7 or later, iPadOS 26.7 or later, or visionOS 27 or later.
  • Disable or uninstall any non‑trusted or suspicious applications that may exploit file path handling.
  • Continuously monitor the filesystem for unexpected write or modification events, and consider employing integrity‑checking tools to detect unauthorized changes.

Generated by OpenCVE AI on September 15, 2026 at 10:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Title Path Handling Vulnerability Allowing Modification of Protected Filesystem Regions
Weaknesses CWE-20
CWE-40

Tue, 15 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple visionos
Vendors & Products Apple
Apple ios And Ipados
Apple visionos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, visionOS 27. An app may be able to modify protected parts of the file system.
References

Subscriptions

Apple Ios And Ipados Visionos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-14T20:47:51.897Z

Reserved: 2026-07-22T00:47:18.621Z

Link: CVE-2026-65411

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-14T21:17:24.743

Modified: 2026-09-14T21:17:24.743

Link: CVE-2026-65411

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T11:00:17Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-40

    Path Traversal: '\\UNC\share\name\' (Windows UNC Share)