Executive brief
An authorization issue in Apple operating systems could allow a malicious application to access sensitive user data. This affects iPhones, iPads, Macs, Apple TVs, and Apple Watches. The vulnerability was caused by improper state management and has been resolved in the latest software updates. Users should update their devices to version 26.6 to protect their private information.
Technical details
An authorization vulnerability existed in multiple Apple operating systems (iOS, iPadOS, macOS, tvOS, visionOS, and watchOS) due to improper state management. A malicious application installed on the device could exploit this flaw to bypass intended authorization checks and access sensitive user data. The issue was addressed by improving how the system manages state during authorization processes. The fix is available in versions 26.6 of the respective operating systems. An attacker would require the ability to run an application on the target device to exploit this vulnerability.
Affected products
- Apple iOS and iPadOS Before 26.6
- Apple macOS Tahoe Before 26.6
- Apple tvOS Before 26.6
- Apple visionOS Before 26.6
- Apple watchOS Before 26.6
Timeline
- 2026-07-27: disclosed
- 2026-07-27: advisory
- 2026-07-27: patched