Description
An authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. An app may gain unauthorized access to Bluetooth.
Published: 2026-09-14
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Bluetooth Access
Action: Patch OS
AI Analysis

Impact

An authorization flaw in Apple devices’ Bluetooth module permits an application to access Bluetooth functionality without the necessary permissions. The vulnerability arises from insufficient state management that allows a malicious or poorly designed app to bypass the normal authorization checks before opening Bluetooth APIs. If an attacker can execute code that triggers this flaw, they could initiate connections, send or harvest data from nearby Bluetooth devices, potentially compromising the confidentiality and integrity of information transmitted over Bluetooth and affecting device operation.

Affected Systems

Apple iOS, iPadOS, macOS Golden Gate, tvOS, visionOS, and watchOS are affected by this flaw. It exists in all releases prior to version 27 on each platform and has been remediated in iOS 27, iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, and watchOS 27.

Risk and Exploitability

The CVSS score of 6.1 indicates moderate severity, and the EPSS score is below 1%, with no listing in CISA’s KEV catalog, indicating limited publicly available exploitation data. Exploitation requires that an attacker be able to run malicious code on the device, typically via a malicious application or local compromise. Under those circumstances the risk is moderate, as unauthorized Bluetooth connectivity could lead to data leakage or device compromise.

Generated by OpenCVE AI on September 20, 2026 at 23:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the operating system to version 27 or later on all affected Apple platforms
  • Disable Bluetooth when not required or enforce strict device‑management policies to restrict Bluetooth usage
  • Verify that all installed applications have only the necessary permissions and monitor app behavior for unexpected Bluetooth activity

Generated by OpenCVE AI on September 20, 2026 at 23:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Title Bluetooth Authorization Defect Allowing Unauthorized Access

Sun, 20 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Bluetooth Access via Improper Authorization
Weaknesses CWE-285

Wed, 16 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-863
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Bluetooth Access via Improper Authorization
Weaknesses CWE-285

Tue, 15 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description An authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. An app may gain unauthorized access to Bluetooth.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-15T16:57:47.608Z

Reserved: 2026-09-01T21:13:17.753Z

Link: CVE-2026-84560

cve-icon Vulnrichment

Updated: 2026-09-15T16:57:28.816Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:32.073

Modified: 2026-09-16T01:06:43.320

Link: CVE-2026-84560

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T23:45:06Z

Weaknesses