Executive brief
Apple has released security updates for iOS, macOS, and visionOS to address a vulnerability that could allow a malicious application to access sensitive user information. This flaw affects various Apple devices including iPhones, iPads, Macs, and the Vision Pro headset. If exploited, an unauthorized app could bypass standard data protections to view private user data, potentially compromising personal privacy.
Technical details
A vulnerability in Apple's operating systems (iOS, iPadOS, macOS Tahoe, and visionOS) was addressed with improved data protection mechanisms. The flaw allows a locally installed application to bypass certain data access restrictions to retrieve sensitive user information. While the specific component was not named in the primary CVE description, the fix involved enhancing data protection logic. The issue is resolved in version 26.5 of the affected operating systems through improved state management or additional validation. An attacker would typically need to entice a user to install a malicious application to exploit this vulnerability.
Affected products
- Apple iOS Before 26.5
- Apple iPadOS Before 26.5
- Apple macOS Tahoe Before 26.5
- Apple visionOS Before 26.5
- Apple Safari Before 26.5
Timeline
- 2026-05-11: disclosed
- 2026-05-11: patched
- 2026-05-11: advisory