Executive brief
A security vulnerability in Apple's mobile and desktop operating systems could allow a malicious application to access sensitive user information. This affects iPhones, iPads, and Mac computers running older versions of their respective software. An exploit could lead to the unauthorized disclosure of private data, potentially compromising user privacy and corporate confidentiality.
Technical details
A vulnerability exists in Apple's operating systems (iOS, iPadOS, and macOS) where an application can bypass intended restrictions to leak sensitive user information. The root cause is a lack of sufficient entitlement checks within the system. An attacker would need to convince a user to install a malicious application on the local device to exploit this flaw. Successful exploitation allows the app to access data it should not have permission to view. Apple has addressed this issue by implementing additional entitlement checks in iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6.
Affected products
- Apple iOS and iPadOS < 26.6
- Apple macOS Sequoia < 15.7.8
- Apple macOS Sonoma < 14.8.8
- Apple macOS Tahoe < 26.6
Timeline
- 2026-07-27: disclosed
- 2026-07-27: patched