Junglewise Threat Intelligence

CVE-2026-64755: Apple iOS and iPadOS authorization bypass via state management

CVE-2026-64755 · Severity: info · CVSS 0 · Published 2026-07-27

Technologies: Apple iPadOS. Vendors: Apple.

Executive brief

A security vulnerability in Apple's mobile operating systems could allow a malicious application to bypass authorization checks. If exploited, an app installed on the device could gain unauthorized access to sensitive user data. This issue has been resolved in the latest software updates for iPhone and iPad.

Technical details

An authorization issue existed in iOS and iPadOS prior to version 26.6. The vulnerability was rooted in improper state management within the operating system's authorization framework. A malicious local application could exploit this flaw to bypass intended permission restrictions and access sensitive user information. Apple addressed the issue by improving state management logic. The fix is available in iOS 26.6 and iPadOS 26.6.

Affected products

  • Apple iOS Before 26.6
  • Apple iPadOS Before 26.6

Timeline

  • 2026-07-27: advisory
  • 2026-07-27: patched

References

Related threats