Description
A logic issue was addressed with improved validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27, watchOS 27. An app may be able to bypass network restrictions.
Published: 2026-09-14
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Network Restriction Bypass
Action: Upgrade OS
AI Analysis

Impact

The vulnerability arises from a logic flaw in Apple’s operating system validation that allows an installed application to bypass the network restrictions normally enforced. The flaw stems from missing validation that should prevent outbound connections to disallowed domains or services. If an attacker installs or modifies a legitimate application, they could transmit data beyond the intended network boundaries, potentially compromising data confidentiality. The likely attack vector is that an attacker must first install or modify a mobile application on the target device, after which the bypass can be realized.

Affected Systems

Apple hardware running iOS, iPadOS, macOS, visionOS, or watchOS prior to major release 27 are vulnerable. The official fix was deployed with iOS 27, iPadOS 27, macOS Golden Gate 27, visionOS 27, and watchOS 27, meaning any device on earlier major releases remains susceptible. Devices running the 27 or later releases are considered not vulnerable.

Risk and Exploitability

The CVSS base score of 4.4 indicates moderate severity, but the EPSS score of less than 1% still indicates a low probability that this flaw will be exploited. The vulnerability is not listed in CISA’s KEV catalog, suggesting no widespread public exploitation. Exploitation requires an attacker to have a foothold on the device through the installation or modification of an application, which limits the attack surface compared to remote or network-based exploits.

Generated by OpenCVE AI on September 20, 2026 at 19:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade all Apple devices to the latest OS release (iOS 27, iPadOS 27, macOS Golden Gate 27, visionOS 27, or watchOS 27).
  • If an upgrade is not immediately possible, configure mobile device management (MDM) to enforce strict network restrictions, block legacy app usage, and quarantine any applications that do not meet enterprise policy.
  • Implement application whitelisting policies to prevent the installation or execution of unapproved applications.

Generated by OpenCVE AI on September 20, 2026 at 19:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Title Logic Flaw Enables Network Restriction Bypass on Apple Devices

Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
Weaknesses CWE-862
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Wed, 16 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Title Bypass of Network Restrictions via Logic Flaw in Apple OS
Weaknesses CWE-285

Tue, 15 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Title Bypass of Network Restrictions via Logic Flaw in Apple OS
Weaknesses CWE-285

Tue, 15 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple visionos
Apple watchos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A logic issue was addressed with improved validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27, watchOS 27. An app may be able to bypass network restrictions.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos Visionos Watchos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-17T16:59:30.131Z

Reserved: 2026-09-01T21:13:17.752Z

Link: CVE-2026-84551

cve-icon Vulnrichment

Updated: 2026-09-17T16:11:52.263Z

cve-icon NVD

Status : Modified

Published: 2026-09-14T21:17:31.240

Modified: 2026-09-17T17:16:49.490

Link: CVE-2026-84551

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T19:45:02Z

Weaknesses