Junglewise Threat Intelligence

CVE-2026-43737: Apple iOS and iPadOS unauthorized motion data access

CVE-2026-43737 · Severity: medium · CVSS 5.5 · Published 2026-09-14

Technologies: Apple Tvos, Apple macOS, Apple watchOS, Apple iPadOS. Vendors: Apple.

Executive brief

Apple's iOS and iPadOS operating systems contained an authorization flaw that allowed applications to access motion sensor data from connected headphones without explicit user permission. This could enable apps to track user activity and movement patterns without consent, compromising user privacy. The issue was fixed in iOS 26.7, 27, and corresponding macOS and iPadOS releases.

Technical details

This is an authorization bypass vulnerability in iOS and iPadOS's motion data access control mechanism. The vulnerability allowed third-party applications to read accelerometer and gyroscope data from connected wireless headphones without obtaining the required user consent prompt. The root cause was insufficient validation of app authorization state before granting access to motion sensors. An attacker would need to craft a malicious app and have a user install it; no network access or special preconditions are required beyond app installation. A successful exploit allows unauthorized collection of motion and activity data, potentially enabling behavioral tracking. The vulnerability was addressed through improved permission validation logic in iOS 26.7, 27, and later versions.

Affected products

  • Apple iOS before 26.7 and 27
  • Apple iPadOS before 26.7 and 27
  • Apple macOS before Golden Gate 27, Sequoia 15.8, Tahoe 26.7
  • Apple tvOS before 27
  • Apple watchOS before 27

Timeline

  • 2026-09-14: disclosed: CVE-2026-43737 disclosed alongside iOS 27 and iPadOS 27 release
  • 2026-09-14: patched: Fixed in iOS 26.7, iPadOS 26.7, iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, watchOS 27

References

Related threats