ZeroHour

CVE-2026-43695

mass

Authorization flaw in Apple OS permission handling lets apps read sensitive data

CVSS
EPSS
Published
()
Modified
AI analysis

CVE-2026-43695 is an authorization issue caused by improper state management in Apple's operating systems, fixed across iOS, iPadOS, macOS, tvOS, visionOS, and watchOS in the September 2026 updates. A malicious or poorly behaved app running on an unpatched device could exploit inconsistent permission state to access sensitive user data beyond what it was authorized to see. Exploitation requires a victim to run the attacker's app on an affected iPhone, iPad, Mac, Apple TV, Apple Watch, or Vision Pro; no user interaction with a remote attacker is implied. All users on versions prior to the fixed releases listed in Apple's advisory are affected. No public proof-of-concept exists, the flaw is not on the CISA KEV list, and no exploitation in the wild has been reported.

What to do: Patch all Apple devices to the fixed releases: iOS/iPadOS 27, macOS Sequoia 15.8, macOS Tahoe 26.7, macOS Golden Gate 27, tvOS 27, visionOS 27, and watchOS 27. Enterprise admins should push these updates via MDM and prioritize them since the flaw allows apps to read sensitive user data. Users and defenders should also audit installed apps and review app permissions under Settings > Privacy & Security to remove any untrusted apps with broad data access.

Affected
Apple iOSversions prior to iOS 27
Apple iPadOSversions prior to iPadOS 27
Apple macOS Golden Gateversions prior to macOS Golden Gate 27
Apple macOS Sequoiaversions prior to macOS Sequoia 15.8
Apple macOS Tahoeversions prior to macOS Tahoe 26.7
Apple tvOSversions prior to tvOS 27
Apple visionOSversions prior to visionOS 27
Apple watchOSversions prior to watchOS 27
Estimated exposure
masslikely hundreds of millions to over a billion devices (all unpatched Apple devices) — Apple has publicly reported roughly 2 billion active devices worldwide, and every device not yet updated to the fixed OS releases listed in the advisory is theoretically exposed, so the unpatched population plausibly runs into the hundreds…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to access sensitive user data.

In the news

Apple Updates Everything, (Mon, Sep 14th)

Apple patched a record 261 vulnerabilities across iOS 27, macOS Golden Gate 27, watchOS 27, and other platforms, with none flagged as exploited.

Apple's annual OS update shipped iOS/iPadOS 27, macOS Golden Gate 27, tvOS 27, watchOS 27, and visionOS 27 plus bug-fix releases for the 26 and 15 branches, fixing a record 261 vulnerabilities. Notable issues include multiple kernel flaws allowing root privilege escalation (CVE-2026-43689, CVE-2026-43691, CVE-2026-43698, CVE-2026-43786), remote code execution in CUPS (CVE-2026-43692), kernel memory corruption via malicious NFS servers (CVE-2026-43686, CVE-2026-43687), and WebKit memory corruption from crafted web content (CVE-2026-43715). No vulnerabilities are labeled as actively exploited, and Apple does not assign per-CVE severities. Users report iOS 26.7 being downloaded when iOS 27 is intended, and tools like Little Snitch and BlockBlock need updates before upgrading to macOS 27.