Executive brief
An authorization flaw in Apple's iOS, iPadOS, macOS, tvOS, visionOS, and watchOS allows third-party applications to gain unauthorized access to Bluetooth connectivity without proper user permission. An attacker could exploit this by distributing a malicious app that silently accesses paired Bluetooth devices (headphones, fitness trackers, smart home devices), potentially enabling eavesdropping, device manipulation, or unwanted pairing without the user's knowledge or consent.
Technical details
This vulnerability is an authorization/state management issue affecting Bluetooth access controls across Apple's operating systems. The root cause involves improper state management in the Bluetooth permission framework, allowing applications to bypass authorization checks. An attacker can create a malicious app that, once installed, gains unauthorized Bluetooth access—typically requiring no special privileges or network connectivity beyond normal app installation. The flaw was addressed through improved state management in iOS 27, iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, and watchOS 27. No public exploit code has been reported in the wild at the time of disclosure.
Affected products
- Apple iOS before 27
- Apple iPadOS before 27
- Apple macOS before Golden Gate 27
- Apple tvOS before 27
- Apple visionOS before 27
- Apple watchOS before 27
Timeline
- 2026-09-14: patched: iOS 27, iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, and watchOS 27 released
- 2026-09-14: disclosed: CVE-2026-84560 published