Executive brief
iOS and related Apple operating systems contain an authorization flaw that may allow an installed app to access sensitive user data without proper consent. The vulnerability was addressed through improved state management controls in iOS 27 and related OS updates released in September 2026. An attacker with a malicious app installed on a user's device could potentially access private information such as contacts, location, or other protected personal data.
Technical details
This vulnerability is an authorization bypass in iOS's state management for permission controls. The root cause involves improper state tracking when apps request access to sensitive user data. An app can exploit this flaw to bypass privacy permission prompts or checks, gaining unauthorized access to protected information (contacts, location, health data, photos, etc.). The attack requires the malicious app to already be installed on the device (local attack vector). Apple addressed this issue by improving state management logic in iOS 27, tvOS 27, iPadOS 27, visionOS 27, and watchOS 27, all released September 14, 2026. The vulnerability affects iPhone 11 and later.
Affected products
- Apple iOS before 27
- Apple iPadOS before 27
- Apple tvOS before 27
- Apple visionOS before 27
- Apple watchOS before 27
Timeline
- 2026-09-14: disclosed
- 2026-09-14: patched