Description
An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27. An app may be able to access sensitive user data.
Published: 2026-09-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized data access
Action: Update OS
AI Analysis

Impact

An authorization issue was discovered in Apple’s operating systems that stems from inadequate state management. The flaw permits applications to obtain sensitive user data without proper authorization, potentially exposing personal information such as contacts, photos, messages, or other privileged content. The vulnerability is classified as an authorization flaw and is mitigated by the vendor’s state management improvements.

Affected Systems

Affected Apple platforms include iOS 26.7 and iOS 27, iPadOS 26.7 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, and tvOS 27. Any device running a pre‑release version of these operating systems without the latest security update is susceptible.

Risk and Exploitability

EPSS score is &lt; 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of widespread exploitation. The CVE notes that an app may be able to access sensitive user data, indicating an authorization weakness that permits reading protected information without proper authorization. The exploit would presumably involve a malicious or compromised application that abuses the state management flaw. The CVE score of 5.5 reflects a moderate impact, but the low EPSS suggests that the risk of exploitation in the wild remains low. The most probable attack vector would involve a malicious application claiming legitimate privileges, but the description does not state whether the flaw requires local access or user interaction; thus, the exact risk profile cannot be precisely quantified.

Generated by OpenCVE AI on September 20, 2026 at 18:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest iOS, iPadOS, macOS, or tvOS update that includes the fix
  • Restrict use of applications that accessed sensitive data until the update is installed
  • Review app permissions to ensure only the minimal necessary privileges are granted

Generated by OpenCVE AI on September 20, 2026 at 18:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
Title Authorization flaw allowing apps to access sensitive data in Apple iOS, iPadOS, macOS, and tvOS

Wed, 16 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Title Authorization Flaw Enables Unauthorized Access to Sensitive Data in Apple Operating Systems
Weaknesses CWE-200
CWE-284

Wed, 16 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-863
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Title Authorization Flaw Enables Unauthorized Access to Sensitive Data in Apple Operating Systems
Weaknesses CWE-200
CWE-284

Tue, 15 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27. An app may be able to access sensitive user data.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-15T15:21:53.025Z

Reserved: 2026-09-01T21:13:23.286Z

Link: CVE-2026-84617

cve-icon Vulnrichment

Updated: 2026-09-15T15:21:43.549Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:36.657

Modified: 2026-09-16T01:05:53.953

Link: CVE-2026-84617

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T19:00:04Z

Weaknesses