Junglewise Threat Intelligence

CVE-2026-84527: Apple iOS and macOS logging information disclosure

CVE-2026-84527 · Severity: medium · CVSS 5.5 · Published 2026-09-14

Technologies: Apple Tvos, Apple watchOS, Apple Visionos, Apple iPadOS, Apple macOS Tahoe, Apple macOS Golden Gate. Vendors: Apple.

Executive brief

A logging mechanism in Apple's iOS and macOS operating systems failed to properly redact sensitive user data, potentially allowing applications to access confidential information through log files. This could expose personal data, credentials, or other sensitive details that should have been hidden. The vulnerability affects iPhone, iPad, and Mac computers running the affected operating system versions.

Technical details

A logging issue in Apple iOS and macOS allows sensitive user data to be exposed in system logs due to inadequate data redaction. The vulnerability is an information disclosure issue in the logging framework that fails to properly sanitize or mask sensitive information before it is written to logs. An application running on the affected system could read these logs to access sensitive user data. The issue is addressed through improved data redaction mechanisms in iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27. No public exploit code has been reported in the wild.

Affected products

  • Apple iOS before 27
  • Apple iPadOS before 27
  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.7
  • Apple tvOS before 27
  • Apple visionOS before 27
  • Apple watchOS before 27

Timeline

  • 2026-09-14: patched: Patches released for iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27
  • 2026-09-14: disclosed: CVE-2026-84527 published

References

Related threats