Junglewise Threat Intelligence

CVE-2026-65348: Apple iOS and iPadOS file system permission bypass

CVE-2026-65348 · Severity: medium · CVSS 5.5 · Published 2026-09-14

Technologies: Apple macOS Golden Gate, Apple iPadOS, Apple macOS Tahoe. Vendors: Apple.

Executive brief

iOS and iPadOS contain a permissions issue that allows malicious apps to modify protected parts of the file system. This could enable attackers to alter system files, compromise device integrity, or access sensitive user data. The vulnerability affects millions of iPhone and iPad users and was patched in iOS 26.7, iOS 27, and corresponding iPadOS versions.

Technical details

A permissions issue in iOS and iPadOS file system handling allows third-party applications to bypass restrictions and modify protected file system regions. The vulnerability stems from insufficient validation or enforcement of app sandboxing boundaries. An attacker can exploit this by distributing a malicious app through the App Store or sideloading; no special privileges or user interaction beyond installation is required. Successful exploitation enables file system tampering, potentially leading to data theft, system compromise, or persistent malware installation. Apple addressed this issue by implementing additional restrictions in iOS 27, iPadOS 27, iOS 26.7, iPadOS 26.7, macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7.

Affected products

  • Apple iOS before 26.7 and 27
  • Apple iPadOS before 26.7 and 27
  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.7

Timeline

  • 2026-09-14: disclosed: CVE-2026-65348 published; iOS 27 and iPadOS 27 released with fix
  • 2026-09-14: patched: Patches available in iOS 26.7, iPadOS 26.7, iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7

References

Related threats