AI analysis
CVE-2026-43695 is an authorization issue caused by improper state management in Apple's operating systems, fixed across iOS, iPadOS, macOS, tvOS, visionOS, and watchOS in the September 2026 updates. A malicious or poorly behaved app running on an unpatched device could exploit inconsistent permission state to access sensitive user data beyond what it was authorized to see. Exploitation requires a victim to run the attacker's app on an affected iPhone, iPad, Mac, Apple TV, Apple Watch, or Vision Pro; no user interaction with a remote attacker is implied. All users on versions prior to the fixed releases listed in Apple's advisory are affected. No public proof-of-concept exists, the flaw is not on the CISA KEV list, and no exploitation in the wild has been reported.
What to do: Patch all Apple devices to the fixed releases: iOS/iPadOS 27, macOS Sequoia 15.8, macOS Tahoe 26.7, macOS Golden Gate 27, tvOS 27, visionOS 27, and watchOS 27. Enterprise admins should push these updates via MDM and prioritize them since the flaw allows apps to read sensitive user data. Users and defenders should also audit installed apps and review app permissions under Settings > Privacy & Security to remove any untrusted apps with broad data access.
Affected
| Apple iOS | versions prior to iOS 27 |
| Apple iPadOS | versions prior to iPadOS 27 |
| Apple macOS Golden Gate | versions prior to macOS Golden Gate 27 |
| Apple macOS Sequoia | versions prior to macOS Sequoia 15.8 |
| Apple macOS Tahoe | versions prior to macOS Tahoe 26.7 |
| Apple tvOS | versions prior to tvOS 27 |
| Apple visionOS | versions prior to visionOS 27 |
| Apple watchOS | versions prior to watchOS 27 |
Estimated exposure
masslikely hundreds of millions to over a billion devices (all unpatched Apple devices) — Apple has publicly reported roughly 2 billion active devices worldwide, and every device not yet updated to the fixed OS releases listed in the advisory is theoretically exposed, so the unpatched population plausibly runs into the hundreds…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
An authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to access sensitive user data.