Junglewise Threat Intelligence

CVE-2026-84636: Apple iOS authorization bypass in state management

CVE-2026-84636 · Severity: medium · CVSS 5.5 · Published 2026-09-14

Technologies: Apple Tvos, Apple Iphone Os, Apple watchOS, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

iOS and related Apple operating systems contain an authorization flaw that may allow an installed app to access sensitive user data without proper consent. The vulnerability was addressed through improved state management controls in iOS 27 and related OS updates released in September 2026. An attacker with a malicious app installed on a user's device could potentially access private information such as contacts, location, or other protected personal data.

Technical details

This vulnerability is an authorization bypass in iOS's state management for permission controls. The root cause involves improper state tracking when apps request access to sensitive user data. An app can exploit this flaw to bypass privacy permission prompts or checks, gaining unauthorized access to protected information (contacts, location, health data, photos, etc.). The attack requires the malicious app to already be installed on the device (local attack vector). Apple addressed this issue by improving state management logic in iOS 27, tvOS 27, iPadOS 27, visionOS 27, and watchOS 27, all released September 14, 2026. The vulnerability affects iPhone 11 and later.

Affected products

  • Apple iOS before 27
  • Apple iPadOS before 27
  • Apple tvOS before 27
  • Apple visionOS before 27
  • Apple watchOS before 27

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched

References

Related threats