Junglewise Threat Intelligence

CVE-2026-86891: Apple macOS Core Bluetooth authorization bypass allowing Bluetooth device information access

CVE-2026-86891 · Severity: low · CVSS 3.5 · Published 2026-09-14

Technologies: Apple macOS, Apple watchOS. Vendors: Apple.

Executive brief

Core Bluetooth is the system component that manages wireless connectivity to Bluetooth devices like headphones, smartwatches, and fitness trackers. An authorization flaw allows malicious apps to read Bluetooth device information without proper user consent, potentially exposing paired device details and user activity patterns. This is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, and watchOS 27.

Technical details

This is an authorization bypass vulnerability in Core Bluetooth caused by improper state management in the permission validation logic. The flaw allows a local app to access Bluetooth device information—including device names, addresses, and connection status—without triggering the required user authorization prompts. The attack requires a malicious app to be installed locally; no network access or special privileges are needed beyond code execution in the app sandbox. An attacker can enumerate paired Bluetooth devices and infer user behavior patterns. The fix involves improved state management in the authorization flow, delivered via security updates to affected macOS and watchOS releases.

Affected products

  • Apple macOS Golden Gate 27, Sequoia 15.8, Tahoe 26.7 and later
  • Apple watchOS 27 and later

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched: Fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, watchOS 27

References

Related threats