Executive brief
A security vulnerability in Apple operating systems could allow a malicious application to access sensitive user data. This affects iPhones, iPads, Macs, Apple TVs, and Apple Watches. Users should update their devices to the latest software versions to prevent unauthorized data access by third-party apps.
Technical details
A vulnerability exists across multiple Apple operating systems (iOS, iPadOS, macOS, tvOS, visionOS, and watchOS) where an application can bypass certain restrictions to access sensitive user data. The root cause was identified as insufficient validation checks within the operating system. An attacker would need to convince a user to install a malicious application to exploit this flaw locally. Apple has addressed the issue by implementing improved checks in the latest OS updates. Affected versions include those prior to iOS/iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6.
Affected products
- Apple iOS and iPadOS < 26.6
- Apple macOS Sequoia < 15.7.8
- Apple macOS Sonoma < 14.8.8
- Apple macOS Tahoe < 26.6
- Apple tvOS < 26.6
- Apple visionOS < 26.6
- Apple watchOS < 26.6
Timeline
- 2026-07-27: disclosed
- 2026-07-27: patched