Description
An authorization issue was addressed with improved access control. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access sensitive user data.
Published: 2026-09-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access to sensitive user data
Action: Update OS
AI Analysis

Impact

An authorization flaw allows an application to read or modify sensitive user data on Apple devices. The weakness stems from a misconfiguration of access controls that was corrected in a recent security update. An attacker who can install a malicious application on a device could exploit the vulnerability to gain data that should be protected by the operating system's privacy safeguards.

Affected Systems

Apple iOS and iPadOS builds older than 26.7 and 27, and Apple macOS releases prior to macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7 are affected. The vulnerability was resolved in the releases cited above; systems running earlier OS versions are exposed.

Risk and Exploitability

The EPSS score of < 1% indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, indicating no publicly known large-scale exploitation at present. However, because the flaw permits local applications to bypass operating‑system controls, a malicious or compromised app could act under the guise of a legitimate process to harvest personal data. The absence of a publicly available exploit vector suggests that the attack requires the attacker to deliver a harmful application to the target device, but once that occurs, the potential for data exfiltration is significant.

Generated by OpenCVE AI on September 20, 2026 at 20:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest updates for iOS 26.7 or later, macOS Golden Gate 27, macOS Sequoia 15.8, or macOS Tahoe 26.7
  • Restrict review app permissions in the device's privacy settings
  • Remove or quarantine any unverified applications that may have been installed during the period the device was running a vulnerable OS version

Generated by OpenCVE AI on September 20, 2026 at 20:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Sun, 20 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Title Authorization Bypass Exposing Sensitive User Data on Apple iOS, iPadOS, and macOS

Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Title Authorization flaw permits app access to sensitive data on iOS, iPadOS, and macOS
Weaknesses CWE-284
CWE-285

Tue, 15 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Title Authorization flaw permits app access to sensitive data on iOS, iPadOS, and macOS
Weaknesses CWE-284
CWE-285

Tue, 15 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Vendors & Products Apple
Apple ios And Ipados
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description An authorization issue was addressed with improved access control. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access sensitive user data.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-17T16:26:36.469Z

Reserved: 2026-09-01T21:13:23.286Z

Link: CVE-2026-84621

cve-icon Vulnrichment

Updated: 2026-09-17T16:26:28.118Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:37.073

Modified: 2026-09-23T19:07:23.413

Link: CVE-2026-84621

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T20:15:04Z

Weaknesses