Description
A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, visionOS 27. An app may be able to bypass certain Privacy preferences.
Published: 2026-09-14
Score: 3.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Privacy breach due to bypass of device privacy controls
Action: Update OS
AI Analysis

Impact

The flaw allows interacting applications to circumvent the operating system’s privacy preferences, resulting in the disclosure of sensitive data that the system was designed to protect. The underlying weakness is an improper handling of privacy settings, consistent with improper disclosure of information (CWE‑200).

Affected Systems

Apple iOS and iPadOS versions earlier than 26.7 and 27, and visionOS earlier than 27 are affected. A vulnerability exists whenever an application can invoke the compromised API or service, allowing it to read data that the user had explicitly restricted through privacy settings.

Risk and Exploitability

The EPSS score is less than 1 % and the vulnerability is not listed in the CISA KEV catalog, and no publicly documented exploits currently exist. In practice, exploitation would require a malicious application running on the device or an attacker capable of delivering such an application, such as through an app store or supply‑chain compromise. Because the weakness directly discloses protected user data, the residual risk remains significant even in the absence of active exploitation evidence.

Generated by OpenCVE AI on September 20, 2026 at 22:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest iOS, iPadOS, or visionOS update (26.7 or later for iOS and iPadOS, 27 for visionOS) to resolve the flaw.
  • Review and, if needed, revoke privacy permissions granted to installed applications in Settings.
  • Monitor the device for unauthorized or tampered applications; remove any suspicious apps or consider a reset if an app appears to have abnormal behavior.

Generated by OpenCVE AI on September 20, 2026 at 22:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Sun, 20 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Title Bypass of Privacy Preferences in Apple iOS, iPadOS, and visionOS
Weaknesses CWE-219
CWE-285

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Title Bypass of Privacy Preferences in Apple iOS, iPadOS, and visionOS
Weaknesses CWE-219
CWE-285

Tue, 15 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple visionos
Vendors & Products Apple
Apple ios And Ipados
Apple visionos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, visionOS 27. An app may be able to bypass certain Privacy preferences.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Visionos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-20T00:04:01.673Z

Reserved: 2026-09-08T16:43:41.872Z

Link: CVE-2026-86887

cve-icon Vulnrichment

Updated: 2026-09-17T14:43:39.078Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:39.660

Modified: 2026-09-21T18:03:25.017

Link: CVE-2026-86887

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T23:00:07Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor