Executive brief
Apple's "Sign In With Apple" is a user authentication service that allows applications to access Apple Account credentials. A flaw in state management allows a malicious app to bypass authentication protections and gain unauthorized access to users' Apple Account information without proper authorization.
Technical details
CVE-2026-20683 is an authentication bypass vulnerability in Apple's Sign In With Apple authentication flow, caused by improper state management in the Apple Account authentication services. A malicious application can exploit this issue to access user Apple Account credentials and sensitive information. The vulnerability is exploitable locally by an installed app without requiring user interaction beyond the initial app installation. Apple addressed this by improving state validation and management in authentication services across iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, and visionOS 27.
Affected products
- Apple iOS 27
- Apple iPadOS 27
- Apple macOS Golden Gate 27, Sequoia 15.8, Tahoe 26.7
- Apple visionOS 27
Timeline
- 2026-09-14: patched: Fixed in iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, and visionOS 27
- 2026-09-14: disclosed: Published by NVD and Apple Security Support