Executive brief
Apple's App Store on iOS and iPadOS may allow third-party applications to access sensitive user data due to insufficient permission checks. An attacker could exploit this by crafting a malicious app that gains unauthorized access to private user information, potentially compromising user privacy and account security.
Technical details
This vulnerability is an authorization bypass in the App Store component affecting iOS and iPadOS. The root cause is insufficient permission validation that allows apps to access sensitive user data beyond their intended sandbox restrictions. The attack vector is local (requires a malicious app installed on the device), with no authentication or user interaction prerequisites beyond installation. An attacker can craft a malicious app to directly access restricted user data. The fix has been addressed with improved permission checks in iOS 26.6, iPadOS 26.6, macOS Tahoe 26.6, and visionOS 26.6 (released July 27, 2026).
Affected products
- Apple iOS prior to 26.6
- Apple iPadOS prior to 26.6
Timeline
- 2026-09-14: disclosed
- 2026-07-27: patched: Fixed in iOS 26.6 and iPadOS 26.6