Junglewise Threat Intelligence

CVE-2026-43695: Apple iOS, iPadOS, and macOS authorization bypass in Accounts

CVE-2026-43695 · Severity: medium · CVSS 5.5 · Published 2026-09-14

Technologies: Apple Tvos, Apple macOS Golden Gate, Apple watchOS, Apple Visionos, Apple iPadOS, Apple macOS Tahoe. Vendors: Apple.

Executive brief

Apple's Accounts subsystem on iOS, iPadOS, and macOS contains a flaw that allows malicious apps to bypass Privacy preferences and access sensitive user data without proper authorization. An attacker can exploit this to access restricted account information and privacy settings, potentially exposing personal data across multiple Apple operating systems.

Technical details

This vulnerability is an authorization bypass in the Accounts framework caused by improper state management. A local malicious application can bypass privacy controls and access restricted account information that should be protected by user preferences. The attack requires the attacker to install and run a malicious app on the target device—no network access or user interaction beyond installation is required. The vulnerability was addressed through improved state management in the Accounts subsystem. Patches are available in iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27 (released September 14, 2026).

Affected products

  • Apple iOS before 27
  • Apple iPadOS before 27
  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.7
  • Apple tvOS before 27
  • Apple visionOS before 27
  • Apple watchOS before 27

Timeline

  • 2026-09-14: disclosed: CVE-2026-43695 disclosed; patches released for iOS 27, iPadOS 27, macOS Golden Gate 27, and other platforms

References

Related threats