Junglewise Threat Intelligence

CVE-2026-84615: Apple iOS and iPadOS authorization bypass in accounts framework

CVE-2026-84615 · Severity: medium · CVSS 5.5 · Published 2026-09-14

Technologies: Apple Tvos, Apple Iphone Os, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

iOS and iPadOS contain an authorization flaw in the accounts framework that could allow malicious apps to bypass privacy preferences and access sensitive user data without proper permission. An attacker who tricks a user into installing a compromised app could read account information, location data, or other protected user information. Apple has patched this vulnerability in iOS 26.7, 27 and iPadOS 26.7, 27.

Technical details

An authorization issue in the accounts framework of iOS and iPadOS was caused by improper state management, allowing apps to bypass privacy preferences and access sensitive user data. The vulnerability affects multiple affected components across Accounts and related frameworks. The attack vector is local, requiring a malicious app to be installed on the device. An attacker can exploit this to access protected user information that should have been blocked by iOS privacy controls. The issue is fixed in iOS 26.7, iOS 27, iPadOS 26.7, and iPadOS 27 through improved state management in the authorization process.

Affected products

  • Apple iOS prior to 26.7 and 27
  • Apple iPadOS prior to 26.7 and 27

Timeline

  • 2026-09-14: disclosed: CVE-2026-84615 published; iOS 27 and iPadOS 27 released with fix
  • 2026-09-14: patched: Patch available in iOS 26.7, iOS 27, iPadOS 26.7, and iPadOS 27

References

Related threats