AI analysis
CVE-2026-43664 is a privacy flaw caused by insufficient data protection in Apple's operating systems, disclosed in Apple's September 2024-style roundup ('Apple Updates Everything'). A malicious or poorly sandboxed app installed on an unpatched device may be able to read sensitive user data that it was never granted permission to access. The flaw requires the attacker to first get a victim to install the app, but exploitation then occurs locally with no further user interaction needed to siphon the exposed data. All users running iOS/iPadOS, macOS, tvOS, or watchOS versions prior to the listed fixes are affected. There is no evidence of in-the-wild exploitation, no public proof of concept, and the issue is not on the CISA KEV list.
What to do: Patch all Apple devices promptly: iPhone/iPad to iOS/iPadOS 26.7 or 27, Macs to macOS Sequoia 15.8, Tahoe 26.7, or Golden Gate 27, Apple TV to tvOS 27, and Apple Watch to watchOS 27; enable automatic updates and push them via MDM in managed fleets. Because the flaw lets a local app over-read user data, audit installed apps and their permission grants on shared or high-risk devices and remove untrusted apps. Watch for a CVSS score and any follow-up Apple advisories, since the current description does not identify which data category (e.g., health, photos, location) is exposed.
Affected
| Apple iOS | All versions prior to iOS 26.7 (fixed in iOS 26.7; also fixed in iOS 27) |
| Apple iPadOS | All versions prior to iPadOS 26.7 (fixed in iPadOS 26.7; also fixed in iPadOS 27) |
| Apple macOS Sequoia | All versions prior to macOS Sequoia 15.8 (fixed in 15.8) |
| Apple macOS Tahoe | All versions prior to macOS Tahoe 26.7 (fixed in 26.7) |
| Apple macOS Golden Gate | All versions prior to macOS Golden Gate 27 (fixed in 27) |
| Apple tvOS | All versions prior to tvOS 27 (fixed in 27) |
| Apple watchOS | All versions prior to watchOS 27 (fixed in 27) |
Estimated exposure
massPotentially 1 billion+ devices until patches are widely adopted — Apple's active installed base exceeds 2 billion iPhones, Macs, and wearables, and essentially every device on unpatched OS versions (i.e., most devices until auto-update completes) is exposed, so the affected population is plausibly in the…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
This issue was addressed with improved data protection. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, watchOS 27. An app may be able to access sensitive user data.