Executive brief
A malicious app can bypass iOS and macOS privacy preferences that restrict access to user accounts and personal data. An attacker could exploit this to gain unauthorized access to sensitive information without user knowledge or consent. This affects multiple Apple operating systems across iPhones, iPads, and Mac computers.
Technical details
CVE-2026-65404 is an authorization bypass vulnerability in the Accounts framework on Apple platforms, caused by improper state management. A malicious application with basic sandbox permissions can bypass privacy checks that normally prevent unauthorized access to account data. The vulnerability requires a malicious app to be installed and executed by the user, but no additional user interaction or special privileges are needed once the app is running. An attacker can achieve unauthorized access to sensitive user account information. Patches are available in iOS 18.7.10, iPadOS 18.7.10, iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.7.8, and macOS Sonoma 14.8.8.
Affected products
- Apple iOS before 18.7.10 and before 27
- Apple iPadOS before 18.7.10 and before 27
- Apple macOS Sequoia before 15.7.8
- Apple macOS Sonoma before 14.8.8
Timeline
- 2026-09-14: disclosed
- 2026-07-27: patched: macOS Sequoia 15.7.8 and macOS Sonoma 14.8.8 released