Executive brief
A security issue in Apple operating systems could allow a malicious application to add new entries to your Contacts list without your permission. This affects iPhones, iPads, Macs, Apple Watches, and Vision Pro headsets. While this does not allow the app to read your existing contacts, it could be used to clutter your address book or facilitate phishing attempts.
Technical details
An authorization vulnerability existed in the Contacts framework across multiple Apple operating systems due to insufficient validation of app permissions. A locally installed malicious application could bypass the requirement for user consent to write new data to the Contacts database. The issue was resolved by implementing stricter validation checks during the contact creation process. The vulnerability is fixed in iOS 26.6, iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, and watchOS 26.6. An attacker would need to have an app already running on the target device to exploit this flaw.
Affected products
- Apple iOS and iPadOS Before 26.6
- Apple macOS Tahoe Before 26.6
- Apple visionOS Before 26.6
- Apple watchOS Before 26.6
Timeline
- 2026-07-27: advisory
- 2026-07-27: patched