Executive brief
A security vulnerability in Apple's operating systems, including iOS, macOS, and watchOS, could allow a malicious application to access sensitive user data. This issue stems from how the system manages internal states, potentially bypassing intended privacy protections. If exploited, a user's private information could be exposed to unauthorized apps installed on the device. Apple has released software updates to address this issue across all affected platforms.
Technical details
A vulnerability in Apple's operating systems was identified where improper state management could lead to unauthorized data access. A malicious application installed on the local system could exploit this flaw to bypass privacy controls and access sensitive user information. The root cause was addressed by improving state management logic within the affected OS components. The vulnerability impacts a wide range of Apple platforms, including iOS, iPadOS, macOS (multiple versions), tvOS, visionOS, and watchOS. Security updates have been released to mitigate this risk; users should update to the latest available versions (e.g., iOS 26.6 or macOS 15.7.8).
Affected products
- Apple iOS and iPadOS < 26.6
- Apple macOS Sequoia < 15.7.8
- Apple macOS Sonoma < 14.8.8
- Apple macOS Tahoe < 26.6
- Apple tvOS < 26.6
- Apple visionOS < 26.6
- Apple watchOS < 26.6
Timeline
- 2026-07-27: advisory
- 2026-07-27: patched