Description
An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, watchOS 27. An app may be able to access Bluetooth device information.
Published: 2026-09-14
Score: 3.5 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access to Bluetooth Device Information
Action: Patch Immediately
AI Analysis

Impact

An authorization flaw driven by inadequate state management lets an application on macOS or watchOS read Bluetooth device information that it should not normally be able to access. The primary effect is the potential disclosure of Bluetooth identifiers, names, or related metadata, which could be used for privacy concerns. No capability to execute code or cause denial of service is indicated in the available description.

Affected Systems

Apple macOS and watchOS systems running versions prior to macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, and watchOS 27 are affected. The fix is included in these OS releases and later.

Risk and Exploitability

The CVSS score is 3.5 and the EPSS score is less than 1%, indicating a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is local: an application installed or running on the device with the standard user context may exploit the flaw. No evidence of remote exploitation or additional prerequisites is reported.

Generated by OpenCVE AI on September 20, 2026 at 21:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest macOS or watchOS update that contains the fix (macOS Golden Gate 27, Sequoia 15.8, Tahoe 26.7, or watchOS 27).
  • Reduce or revoke unnecessary Bluetooth permissions granted to applications and monitor which apps can query Bluetooth device information.
  • Turn off Bluetooth when it is not required or apply stricter organization‑wide controls around Bluetooth usage.

Generated by OpenCVE AI on September 20, 2026 at 21:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Access to Bluetooth Device Information via Improper Authorization
Weaknesses CWE-284

Fri, 18 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Access to Bluetooth Device Information via Improper Authorization
Weaknesses CWE-284

Tue, 15 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Apple watchos
Vendors & Products Apple
Apple macos
Apple watchos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, watchOS 27. An app may be able to access Bluetooth device information.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-17T14:45:21.957Z

Reserved: 2026-09-08T16:43:41.872Z

Link: CVE-2026-86891

cve-icon Vulnrichment

Updated: 2026-09-17T14:45:04.358Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:40.067

Modified: 2026-09-18T14:25:18.230

Link: CVE-2026-86891

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T21:30:06Z

Weaknesses