Description
An information disclosure issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, watchOS 27. A malicious application may be able to leak sensitive user information.
Published: 2026-09-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Update
AI Analysis

Impact

This vulnerability allows a malicious application to leak sensitive user information, exposing data that should remain private. The flaw arises from improper state management within the operating system, which can be exploited to read arbitrary data from the device. It is a CWE-200 Information Exposure vulnerability, indicating a weakness in confidentiality protection.

Affected Systems

Apple macOS (versions prior to Golden Gate 27) and Apple watchOS (versions prior to Golden Gate 27) are affected. The issue is fixed in macOS Golden Gate 27 and watchOS 27.

Risk and Exploitability

CVSS Score of 5.5 indicates medium severity, and EPSS < 1% indicates a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be local: a malicious application that the user installs or runs on the device can trigger the information leak. Because the flaw does not require network access or elevated privileges beyond the owning user, the overall risk remains moderate but potentially significant for sensitive data exposure.

Generated by OpenCVE AI on September 20, 2026 at 19:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update macOS to version Golden Gate 27 or later
  • Update watchOS to version Golden Gate 27 or later
  • Restrict installation of third‑party applications to trusted sources and monitor app permissions

Generated by OpenCVE AI on September 20, 2026 at 19:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Title Improper State Management Allows Information Disclosure on macOS and watchOS

Thu, 17 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*

Wed, 16 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Title Improper State Management Enables Sensitive Information Disclosure

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Title Improper State Management Enables Sensitive Information Disclosure
Weaknesses CWE-200

Tue, 15 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Apple watchos
Vendors & Products Apple
Apple macos
Apple watchos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description An information disclosure issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, watchOS 27. A malicious application may be able to leak sensitive user information.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-15T15:13:41.426Z

Reserved: 2026-09-01T21:13:17.757Z

Link: CVE-2026-84586

cve-icon Vulnrichment

Updated: 2026-09-15T15:13:32.443Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:34.680

Modified: 2026-09-17T15:57:43.997

Link: CVE-2026-84586

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T19:30:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor