Junglewise Threat Intelligence

CVE-2026-84621: Apple iOS and iPadOS authorization bypass

CVE-2026-84621 · Severity: medium · CVSS 5.5 · Published 2026-09-14

Technologies: Apple iPadOS. Vendors: Apple.

Executive brief

An authorization flaw in iOS and iPadOS allows malicious apps to access sensitive user data by bypassing access controls. This could enable an attacker to steal personal information, location data, contacts, or other private information without the user's knowledge or consent.

Technical details

An authorization issue in the Accessibility framework of iOS and iPadOS permits an app to access sensitive user data without proper permission checks. The vulnerability is rooted in insufficient access control validation. Attack requires installation of a malicious app; no network access or user interaction beyond app installation is needed. An attacker can exfiltrate protected user data. Apple patched this in iOS 26.7, iOS 27, iPadOS 26.7, and iPadOS 27 with improved access control mechanisms.

Affected products

  • Apple iOS before 26.7 and before 27
  • Apple iPadOS before 26.7 and before 27

Timeline

  • 2026-09-14: disclosed: Published on NVD and Apple security advisory
  • 2026-09-14: patched: Fixed in iOS 26.7, iOS 27, iPadOS 26.7, iPadOS 27

References

Related threats