Executive brief
Apple's Accessibility framework, which enables assistive technologies for users with disabilities, contains a data protection flaw that allows apps to access sensitive user data without proper authorization. An attacker could exploit this by distributing a malicious app that leverages the Accessibility system to harvest personal information, compromising user privacy across iOS, iPadOS, and macOS devices.
Technical details
CVE-2026-43664 is a data protection vulnerability in Apple's Accessibility framework that permits unauthorized access to sensitive user data. The root cause involves insufficient data protection mechanisms in the Accessibility component, allowing apps to read information they should not have access to. The vulnerability requires a malicious app to be installed on the target device (local attack vector with low privileges required). An attacker can craft an app that uses Accessibility APIs to enumerate and access protected user data. Apple addressed this issue with improved data protection logic in iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, and watchOS 27, released September 14, 2026.
Affected products
- Apple iOS before 27
- Apple iPadOS before 27
- Apple macOS Golden Gate before 27
- Apple macOS Sequoia before 15.8
- Apple macOS Tahoe before 26.7
- Apple tvOS before 27
- Apple watchOS before 27
Timeline
- 2026-09-14: disclosed: Published on NVD
- 2026-09-14: patched: Fixed in iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, watchOS 27