Executive brief
Apple's Accessibility framework, which provides assistive features for users with disabilities across iOS, iPadOS, and macOS, contains a data protection flaw that allows installed applications to access sensitive user data without proper authorization. An attacker with a malicious app could exploit this to exfiltrate private user information, compromising privacy even if the app's declared permissions don't justify such access.
Technical details
A data protection vulnerability in Apple's Accessibility framework permits installed applications to bypass intended access controls and read sensitive user data. The vulnerability is triggered when an app exploits improper data protection mechanisms in the Accessibility subsystem. Attack precondition: the attacker's app must be installed on the device; no network access is required. An adversary can achieve unauthorized data exfiltration affecting user privacy. The issue was addressed via improved data protection in iOS 26.7, iOS 27, iPadOS 26.7, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27, and watchOS 27.
Affected products
- Apple iOS before 26.7 and before 27
- Apple iPadOS before 26.7 and before 27
- Apple macOS Golden Gate before 27
- Apple macOS Sequoia before 15.8
- Apple macOS Tahoe before 26.7
- Apple visionOS before 27
- Apple watchOS before 27
Timeline
- 2026-09-14: disclosed