Executive brief
Apple's iOS and related operating systems contain a permissions validation flaw in the APFS filesystem that allows applications to modify protected system files. An attacker controlling a malicious app could gain unauthorized access to critical system files, potentially compromising device security, user data, and system integrity across multiple Apple platforms including iPhones, iPads, and Macs.
Technical details
A permissions issue exists in APFS (Apple File System) where inadequate path validation allows applications to bypass restrictions on system file access. The vulnerability is addressed through improved path validation logic. An app can leverage this flaw to write to protected system files without proper authorization checks. The issue affects multiple platforms including iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. Patches were released on September 14, 2026 across all affected platforms.
Affected products
- Apple iOS 27
- Apple iPadOS 27
- Apple macOS Golden Gate 27
- Apple macOS Sequoia 15.8
- Apple macOS Tahoe 26.7
- Apple tvOS 27
- Apple visionOS 27
- Apple watchOS 27
Timeline
- 2026-09-14: disclosed: CVE-2026-84609 disclosed alongside iOS 27, iPadOS 27, and macOS updates
- 2026-09-14: patched: Patches released for iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27