AI analysis
CVE-2026-20683 is an authentication weakness in Apple's Sign In With Apple flow caused by improper state management, allowing an app on the device to abuse the authentication flow and gain access to the user's Apple Account. Exploitation requires a malicious or vulnerable app already present on an affected iPhone, iPad, Mac, or Vision Pro; no separate network exposure is needed. A successful attacker could potentially access the victim's Apple Account, which typically gates iCloud data, purchases, and linked services. The flaw affects devices running iOS/iPadOS versions prior to 27, macOS prior to Sequoia 15.8 / Tahoe 26.7 / Golden Gate 27, and visionOS prior to 27, all fixed in Apple's September 2025 release wave. No public proof-of-concept or in-the-wild exploitation has been reported, and the issue is not on the CISA KEV list.
What to do: Update all Apple devices immediately to iOS 27 / iPadOS 27, macOS Sequoia 15.8, macOS Tahoe 26.7, macOS Golden Gate 27, or visionOS 27, and use MDM or Apple's rapid security response tooling to force fleet-wide patching. Review the list of apps authorized to use Sign In With Apple (Settings > Apple Account > Sign-In and Security) and revoke access for any untrusted or unknown third-party apps. Audit enterprise app inventories for apps that initiate Sign In With Apple flows, since a malicious app on the device is the delivery vector.
Affected
| Apple iOS | versions prior to iOS 27 |
| Apple iPadOS | versions prior to iPadOS 27 |
| Apple macOS Golden Gate | versions prior to macOS Golden Gate 27 |
| Apple macOS Sequoia | versions prior to macOS Sequoia 15.8 |
| Apple macOS Tahoe | versions prior to macOS Tahoe 26.7 |
| Apple visionOS | versions prior to visionOS 27 |
Estimated exposure
mass≈1-2 billion Apple devices potentially exposed until patched (Apple's active install base exceeds 2 billion devices) — Apple has publicly stated more than 2 billion active devices in use, and any unpatched iPhone, iPad, Mac, or Vision Pro is potentially affected until updated to the fixed releases.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
An authentication issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27. An app may be able to use the Sign In With Apple authentication flow to access the user's Apple Account.