Junglewise Threat Intelligence

CVE-2026-84491: Apple iOS and iPadOS Accessibility permission disclosure

CVE-2026-84491 · Severity: medium · CVSS 5.5 · Published 2026-09-14

Technologies: Apple Tvos, Apple macOS, Apple Iphone Os, Apple watchOS, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

Apple's iOS and iPadOS Accessibility framework contains a permissions issue that could allow a malicious app to access sensitive user data without proper authorization. This affects all modern iPhones and iPads running vulnerable versions. An attacker could exploit this to steal personal information, contact details, location data, or other sensitive information stored on the device.

Technical details

A permissions issue in the Accessibility framework on iOS and iPadOS allows an installed application to bypass data protection controls and access sensitive user data. The vulnerability exists due to insufficient restrictions on what the Accessibility service can access. An attacker must have the ability to install a malicious app on the target device (local attack vector). The issue was addressed with additional restrictions to the Accessibility framework permissions. Fixes are available in iOS 26.7, iPadOS 26.7, iOS 27, and iPadOS 27 released on September 14, 2026.

Affected products

  • Apple iOS before 26.7 and 27
  • Apple iPadOS before 26.7 and 27

Timeline

  • 2026-09-14: patched: Patched in iOS 26.7, iPadOS 26.7, iOS 27, and iPadOS 27
  • 2026-09-14: disclosed: CVE-2026-43664 published

References

Related threats