Junglewise Threat Intelligence

CVE-2026-84624: Apple iOS, iPadOS, and macOS permissions bypass via path validation

CVE-2026-84624 · Severity: medium · CVSS 5.5 · Published 2026-09-14

Technologies: Apple macOS Golden Gate, Apple Visionos, Apple iPadOS, Apple macOS Tahoe. Vendors: Apple.

Executive brief

A permissions vulnerability in Apple's operating systems allows sandboxed applications to access files that should be restricted by the sandbox. This affects iPhones, iPads, Macs, and Vision Pro devices. An attacker can exploit this by creating a malicious app that reads or modifies sensitive files, potentially compromising user privacy and device security.

Technical details

This is a permissions issue (sandbox escape) caused by insufficient path validation in the file system access controls. The vulnerability allows a sandboxed app to bypass restrictions and access restricted files on the device. The attack vector is local (requires an app to be installed and run on the device). The fix involves improved path validation to properly enforce sandbox boundaries, and patches are available in iOS 26.7, iPadOS 26.7, iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, and visionOS 27.

Affected products

  • Apple iOS before 26.7 and 27
  • Apple iPadOS before 26.7 and 27
  • Apple macOS Sequoia before 15.8
  • Apple macOS Golden Gate before 27
  • Apple macOS Tahoe before 26.7
  • Apple visionOS before 27

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched: Fixed in iOS 26.7, iPadOS 26.7, iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, and visionOS 27

References

Related threats