Junglewise Threat Intelligence

CVE-2026-84617: Apple iOS and iPadOS authorization bypass in Accounts

CVE-2026-84617 · Severity: medium · CVSS 5.5 · Published 2026-09-14

Technologies: Apple iPadOS. Vendors: Apple.

Executive brief

iOS and iPadOS contain an authorization flaw in the Accounts system component that could allow a malicious app to bypass privacy preferences and access sensitive user data. An attacker with a malicious app installed on a device could potentially circumvent the intended access controls, leading to unauthorized data exposure without the user's explicit knowledge or consent.

Technical details

CVE-2026-65404 is an authorization bypass vulnerability in the Accounts framework on iOS and iPadOS. The root cause is improper state management in authorization checks. A malicious application running locally on the device can exploit this vulnerability to bypass privacy preference checks and access restricted user account information without proper authorization. The attack requires the attacker to have a malicious app installed on the target device (local attack vector with user interaction for app installation). The fix improves state management in the authorization process to properly enforce privacy preferences.

Affected products

  • Apple iOS prior to 26.7 and 27
  • Apple iPadOS prior to 26.7 and 27

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched: Fixed in iOS 26.7, iPadOS 26.7, iOS 27, and iPadOS 27

References

Related threats