Junglewise Threat Intelligence

CVE-2026-65406: Apple Accessibility logic issue allowing sensitive user data access

CVE-2026-65406 · Severity: medium · CVSS 5.5 · Published 2026-09-14

Technologies: Apple Tvos, Apple Visionos, Apple iPadOS, Apple macOS Tahoe, Apple macOS Golden Gate. Vendors: Apple.

Executive brief

Apple's Accessibility framework contains a logic flaw that could allow apps to access sensitive user information without proper authorization. The vulnerability affects iOS, iPadOS, macOS, tvOS, and visionOS systems. An attacker could exploit this via a malicious app to retrieve private user data, potentially compromising user privacy and confidentiality.

Technical details

A logic issue in Apple's Accessibility framework was addressed through improved validation. The vulnerability allows an app to bypass proper authorization checks and access sensitive user data. The attack vector is local (requires a malicious app installed on the device) with no special privileges or user interaction required beyond the initial app installation. An attacker can retrieve private user information that should be protected. The issue is patched in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, and visionOS 27.

Affected products

  • Apple iOS before 26.7 and before 27
  • Apple iPadOS before 26.7 and before 27
  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.7
  • Apple tvOS before 27
  • Apple visionOS before 27

Timeline

  • 2026-09-14: patched
  • 2026-09-14: disclosed

References

Related threats