Description
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, watchOS 27. An app may be able to access sensitive user data.
Published: 2026-09-14
Score: n/a
EPSS: n/a
KEV: No
Impact: Unauthorized access to sensitive user data
Action: Immediate Update
AI Analysis

Impact

A permissions issue that allowed an application to access sensitive user data was present in earlier versions of several Apple operating systems. The issue was resolved by adding extra restrictions in the 27th release for iOS, iPadOS, macOS, tvOS, and watchOS. This flaw could let an app read or collect data that it should not have been able to access, potentially exposing personal information to malicious actors.

Affected Systems

Apple iOS, iPadOS, macOS, tvOS, and watchOS are affected. Devices running versions prior to the 27th release are vulnerable, as the fix was only introduced in those later releases.

Risk and Exploitability

The vulnerability is a classic improper access control problem that could be exploited by any third‑party application with elevated permissions. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog, but the potential for data exposure and the lack of a public exploit imply a moderate to high risk. An attacker would need to convince the user to install a malicious or compromised application, which could then read protected data.

Generated by OpenCVE AI on September 15, 2026 at 08:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update your device to iOS, iPadOS, macOS, tvOS, or watchOS version 27 or later.
  • If updating is not immediately possible, reduce the permissions granted to installed applications by disabling access to sensitive data in the device’s privacy settings.
  • Review installed applications and remove any that have unnecessary permissions to access user data.

Generated by OpenCVE AI on September 15, 2026 at 08:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Title Permissions Issue Allowing App Access to Sensitive User Data
Weaknesses CWE-284

Tue, 15 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple watchos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, watchOS 27. An app may be able to access sensitive user data.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-14T20:49:41.384Z

Reserved: 2026-09-08T16:43:41.871Z

Link: CVE-2026-86884

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-14T21:17:39.340

Modified: 2026-09-14T21:17:39.340

Link: CVE-2026-86884

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T08:15:13Z

Weaknesses