Description
This issue was addressed with additional entitlement checks. This issue is fixed in Safari 27, iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. An app may be able to access sensitive user data.
Published: 2026-09-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Access
Action: Patch Now
AI Analysis

Impact

An application can bypass entitlement checks in Apple Safari, iOS, iPadOS, macOS, and visionOS, allowing it to read or modify sensitive user data that should be protected. The flaw is an authorization weakness that grants unauthorized access to confidential information, potentially leading to data leakage or manipulation.

Affected Systems

The vulnerability affects any installed version of Safari, iOS, iPadOS, macOS, or visionOS that is earlier than the security updates. Unsigned or legacy releases of Safari before version 27, iOS and iPadOS before 26.7 or 27, macOS Golden Gate before 27, and visionOS before 27 remain vulnerable.

Risk and Exploitability

Based on the description, it is inferred that exploitation requires a local or malicious application that successfully evades the added entitlement checks. The CVSS score of 5.5 indicates moderate severity, and the EPSS score of less than 1 % suggests a very low likelihood of active exploitation. The vulnerability is not listed in the CISA KEV catalog, implying no widespread exploitation has been observed. The overall risk remains moderate with a low probability of an active attack at present.

Generated by OpenCVE AI on September 21, 2026 at 00:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Safari 27, iOS 26.7 or 27, iPadOS 26.7 or 27, macOS Golden Gate 27, or visionOS 27 to apply the entitlement-check fix.
  • Limit app entitlements through device‑management policies to reduce the attack surface.
  • Monitor application data‑access logs for unusual activity and investigate any unexpected reads of sensitive data.

Generated by OpenCVE AI on September 21, 2026 at 00:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Title Authorization Bypass Enables Unauthorized Data Access in Apple Platforms

Sun, 20 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
Title App Unauthorized Access to Sensitive User Data Due to Improper Entitlement Checks in Apple Web Browsers and Operating Systems
Weaknesses CWE-269
CWE-284

Fri, 18 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Wed, 16 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
Title App Unauthorized Access to Sensitive User Data Due to Improper Entitlement Checks in Apple Web Browsers and Operating Systems
Weaknesses CWE-269
CWE-284

Tue, 15 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple safari
Apple visionos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple safari
Apple visionos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description This issue was addressed with additional entitlement checks. This issue is fixed in Safari 27, iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. An app may be able to access sensitive user data.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos Safari Visionos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-16T13:20:50.732Z

Reserved: 2026-09-08T16:43:41.873Z

Link: CVE-2026-86897

cve-icon Vulnrichment

Updated: 2026-09-16T13:20:33.308Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:40.587

Modified: 2026-09-18T12:22:34.720

Link: CVE-2026-86897

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:30:06Z

Weaknesses