Description
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, visionOS 27, watchOS 27. An app may be able to access sensitive user data.
Published: 2026-09-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Data Exposure
Action: Patch ASAP
AI Analysis

Impact

The vulnerability originates from a missing permission check, allowing an application to access sensitive user data without appropriate authorization. This weakness exemplifies improper authorization (CWE-269) and could let an app read protected data beyond its granted permissions. Based on the description, it is inferred that the likely attack vector is the installation or running of a malicious application that exploits this missing permission check to read protected data.

Affected Systems

All builds of Apple’s iOS, iPadOS, visionOS, and watchOS prior to version 27 are affected. Devices running iOS 27, iPadOS 27, visionOS 27, or watchOS 27 are not affected, as the missing permission restrictions have been fixed.

Risk and Exploitability

The EPSS score is less than 1 % and the vulnerability is not listed in CISA’s KEV catalog, indicating a low probability of exploitation. The flaw permits applications to read protected data when the user installs or runs the app, creating a confidentiality risk. The CVSS score of 5.5 indicates that the vulnerability poses a moderate threat.

Generated by OpenCVE AI on September 20, 2026 at 20:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the device to iOS 27, iPadOS 27, visionOS 27, or watchOS 27 to apply the patch that adds the missing permission checks.
  • Revoke any broad permissions granted to third‑party apps that are not explicitly required for the app’s functionality, enforcing applications and review their permission usage; uninstall or block any app that requests unnecessary access to sensitive data.
  • Implement device‑management policies that prevent privilege escalation and enforce the least‑privilege principle for all applications.

Generated by OpenCVE AI on September 20, 2026 at 20:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Title Missing Permission Check Allows App Access to Sensitive User Data

Thu, 17 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Title Permission Issue Allows App Access to Sensitive User Data on Apple Devices
Weaknesses CWE-285

Tue, 15 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Title Permission Issue Allows App Access to Sensitive User Data on Apple Devices
Weaknesses CWE-285

Tue, 15 Sep 2026 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple visionos
Apple watchos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, visionOS 27, watchOS 27. An app may be able to access sensitive user data.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Visionos Watchos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-17T14:49:05.873Z

Reserved: 2026-09-01T21:13:17.759Z

Link: CVE-2026-84603

cve-icon Vulnrichment

Updated: 2026-09-17T14:48:59.267Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:35.817

Modified: 2026-09-17T15:57:07.463

Link: CVE-2026-84603

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T21:00:05Z

Weaknesses
  • CWE-269

    Improper Privilege Management