Junglewise Threat Intelligence

CVE-2026-64711: Apple iOS and macOS sensitive information leak via entitlement bypass

CVE-2026-64711 · Severity: info · Published 2026-07-27

Technologies: Apple macOS Sonoma, Apple iPadOS. Vendors: Apple.

Executive brief

A security vulnerability in Apple's mobile and desktop operating systems could allow a malicious application to access sensitive user information. This affects iPhones, iPads, and Mac computers running older versions of their respective software. An exploit could lead to the unauthorized disclosure of private data, potentially compromising user privacy and corporate confidentiality.

Technical details

A vulnerability exists in Apple's operating systems (iOS, iPadOS, and macOS) where an application can bypass intended restrictions to leak sensitive user information. The root cause is a lack of sufficient entitlement checks within the system. An attacker would need to convince a user to install a malicious application on the local device to exploit this flaw. Successful exploitation allows the app to access data it should not have permission to view. Apple has addressed this issue by implementing additional entitlement checks in iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6.

Affected products

  • Apple iOS and iPadOS < 26.6
  • Apple macOS Sequoia < 15.7.8
  • Apple macOS Sonoma < 14.8.8
  • Apple macOS Tahoe < 26.6

Timeline

  • 2026-07-27: disclosed
  • 2026-07-27: patched

References

Related threats