Executive brief
An authorization vulnerability in Apple's operating systems could allow a malicious application to access sensitive user data. This issue affects a wide range of devices including iPhones, iPads, Macs, and Apple Watches. By exploiting this flaw, an app could bypass intended security restrictions to view private information it should not have access to. Apple has released software updates to correct how the system manages authorization states.
Technical details
An authorization vulnerability exists in the Accounts component of multiple Apple operating systems due to improper state management. A local attacker can exploit this by using a malicious application to bypass authorization checks and gain access to sensitive user information. The issue was addressed by improving state management within the affected component. Patches are available in iOS 18.7.9/26.4, iPadOS 18.7.9/26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, visionOS 26.4, and watchOS 26.4.
Affected products
- Apple iOS up to 18.7.9, up to 26.4
- Apple iPadOS up to 18.7.9, up to 26.4
- Apple macOS Sequoia up to 15.7.5
- Apple macOS Sonoma up to 14.8.5
- Apple macOS Tahoe up to 26.4
- Apple visionOS up to 26.4
- Apple watchOS up to 26.4
Timeline
- 2026-03-24: disclosed
- 2026-03-24: patched
- 2026-03-25: advisory