Junglewise Threat Intelligence

CVE-2026-65353: Apple Account authorization issue in state management

CVE-2026-65353 · Severity: medium · CVSS 5.5 · Published 2026-09-14

Technologies: Apple macOS, Apple Iphone Os, Apple iPadOS. Vendors: Apple.

Executive brief

An authorization flaw in Apple Account (a system component that manages user authentication and account permissions on Apple devices) allows malicious apps to access sensitive user data by circumventing proper state checks. An attacker can exploit this without requiring special permissions or user interaction, potentially exposing personal information stored in the user's account.

Technical details

This is an authorization bypass vulnerability (CVE-2026-65353) in the Apple Account framework caused by inadequate state management during permission validation. The vulnerability allows a malicious app to access sensitive user data by exploiting a race condition or improper state handling in the authorization logic. The attack requires only that a malicious app be installed on the device—no network access, authentication bypass, or user interaction beyond app installation is necessary. Apple addressed this by implementing improved state management to properly validate authorization state before granting access to sensitive user data. The fix is available in iOS 26.6, iPadOS 26.6, and macOS Tahoe 26.6, released July 27, 2026.

Affected products

  • Apple iOS prior to 26.6
  • Apple iPadOS prior to 26.6
  • Apple macOS Tahoe prior to 26.6

Timeline

  • 2026-09-14: disclosed
  • 2026-07-27: patched: iOS 26.6, iPadOS 26.6, macOS Tahoe 26.6 released

References

Related threats