Executive brief
A path handling issue in iOS, iPadOS, and macOS allows an app to access user-sensitive data through improper validation of file paths. An attacker could exploit this vulnerability to gain unauthorized access to private user information stored on the device without requiring explicit user permission or authentication.
Technical details
This vulnerability is a path handling issue in Apple's operating systems that was addressed with improved validation logic. The root cause involves insufficient validation of file system paths, which could allow a malicious app to bypass access controls and read sensitive user data. The attack vector is local, requiring a malicious app to be installed on the device. No network access or user interaction is required beyond the initial app installation. Apple has patched this issue in iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7.
Affected products
- Apple iOS before 27
- Apple iPadOS before 27
- Apple macOS Golden Gate before 27
- Apple macOS Sequoia before 15.8
- Apple macOS Tahoe before 26.7
Timeline
- 2026-09-14: disclosed: Published via NVD
- 2026-09-14: patched: Fixed in iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7