Description
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. An app may be able to access sensitive user data.
Published: 2026-09-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Access
Action: Update Device
AI Analysis

Impact

A permissions flaw in multiple Apple operating systems allows an installed application to read sensitive user data that it should not be able to access. The vulnerability was mitigated by adding restrictions in later releases. The impact is the disclosure of personal or device‑specific information to an unauthorized application.

Affected Systems

Apple iOS, iPadOS, macOS, tvOS, visionOS, and watchOS are affected. The fix is implemented in iOS 26.7, iOS 27, iPadOS 26.7, iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, and watchOS 27. Devices running earlier versions of these operating systems remain vulnerable.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate severity. The EPSS score of less than 1% suggests a very low probability of exploitation in the general population. The vulnerability is not listed in CISA’s KEV catalog. The attack vector appears to be local, requiring an installed or compromised app with elevated privileges to exploit the flaw; however, this is inferred from the description and not confirmed. No publicly reported exploitation examples are known as of the data available.

Generated by OpenCVE AI on September 20, 2026 at 22:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the device to at least the fixed OS versions listed above to apply the new permission restrictions.
  • Only install applications from trusted sources such as Apple’s App Store and verify that each app requests only necessary permissions.
  • Review and manage installed app permissions in the device settings, revoking any that are unnecessary or suspicious.

Generated by OpenCVE AI on September 20, 2026 at 22:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Title Permissions Issue Allowing App Access to Sensitive User Data
Weaknesses CWE-285

Wed, 16 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Title Permissions Issue Allowing App Access to Sensitive User Data
Weaknesses CWE-285

Tue, 15 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. An app may be able to access sensitive user data.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-15T17:14:53.864Z

Reserved: 2026-09-01T20:50:08.321Z

Link: CVE-2026-84491

cve-icon Vulnrichment

Updated: 2026-09-15T17:14:47.257Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:26.760

Modified: 2026-09-16T01:08:23.377

Link: CVE-2026-84491

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T22:45:05Z

Weaknesses