Description
A permissions issue was addressed with improved path validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27. A sandboxed app may be able to access restricted files.
Published: 2026-09-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Potential sandbox escape allowing a malicious or compromised application to read or modify restricted files on the device
Action: Apply patch
AI Analysis

Impact

A permissions flaw due to inadequate path validation can allow a sandboxed application to access files outside its intended scope. This path‑traversal weakness enables the app to read or modify restricted files on the device, potentially compromising confidential data and altering system integrity. The impact is limited to the device but can degrade overall reliability if critical files are altered.

Affected Systems

Apple operating systems affected include iOS 26.7 and later, iPadOS 26.7 and later, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, and visionOS 27 and later. Devices running those OS versions may be vulnerable until updated.

Risk and Exploitability

The CVSS score of 5.5 reflects moderate severity, and the EPSS score of < 1 % suggests a very low probability of active exploitation. The vulnerability is local, requiring a sandboxed or malicious app to exploit the path‑validation flaw, and is not an over‑the‑network attack vector. It is not listed in CISA’s KEV catalog.

Generated by OpenCVE AI on September 20, 2026 at 22:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the device to the latest supported OS that includes the path validation fix (iOS 26.7 or newer, iPadOS 26.7 or newer, macOS Golden Gate 27 or newer, macOS Sequoia 15.8 or newer, macOS Tahoe 26.7 or newer, visionOS 27 or newer).
  • Enable automatic OS updates or configure Mobile Device Management to enforce timely security patches.
  • For devices that cannot upgrade immediately, use Mobile Device Management to block the installation of non‑Apple Store or untrusted applications and enforce strict sandboxing policies until the fix is applied.

Generated by OpenCVE AI on September 20, 2026 at 22:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Sun, 20 Sep 2026 22:45:00 +0000

Type Values Removed Values Added
Title Path Traversal Vulnerability in Apple OS Enabling Sandboxed Apps to Read or Modify Restricted Files

Wed, 16 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Title Sandboxed App Potentially Accessing Restricted Files Due to Path Validation Bug
Weaknesses CWE-22
CWE-284

Tue, 15 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
Title Sandboxed App Potentially Accessing Restricted Files Due to Path Validation Bug
Weaknesses CWE-22
CWE-284

Tue, 15 Sep 2026 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple visionos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple visionos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed with improved path validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27. A sandboxed app may be able to access restricted files.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos Visionos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-16T13:27:23.121Z

Reserved: 2026-09-01T21:13:23.286Z

Link: CVE-2026-84624

cve-icon Vulnrichment

Updated: 2026-09-16T13:26:36.304Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:37.393

Modified: 2026-09-23T19:04:05.247

Link: CVE-2026-84624

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T22:30:06Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')