ZeroHour

CVE-2026-65406

mass

App Data-Access Logic Flaw in Apple iOS, iPadOS, macOS, tvOS, visionOS

CVSS 3.1
5.5 medium
EPSS
Published
()
Modified
AI analysis

CVE-2026-65406 is a logic flaw caused by insufficient validation in Apple's operating systems, addressed with improved checks in a record-setting wave of Apple patches. An app installed on an affected device may be able to access sensitive user data beyond what its permissions should allow, meaning exploitation requires the victim to first install a malicious or compromised app (e.g., via App Store, sideloading, or enterprise distribution) rather than a remote network vector. Successful abuse gives the attacker's app unauthorized access to sensitive user data, a privacy/confidentiality breach rather than code execution. Affected users are those running iOS and iPadOS prior to the fixes in 26.7 and 27, macOS Sequoia prior to 15.8, macOS Tahoe prior to 26.7, macOS Golden Gate prior to 27, tvOS prior to 27, and visionOS prior to 27. There is no known in-the-wild exploitation, no public PoC, and the CVE is not on CISA's KEV list, though CVSS has not yet been scored and details may evolve.

What to do: Patch promptly: update iPhones and iPads to iOS/iPadOS 26.7 or 27, Macs to macOS Sequoia 15.8, Tahoe 26.7, or Golden Gate 27, Apple TVs to tvOS 27, and Vision Pro headsets to visionOS 27, with MDM/IT fleets pushing these updates organization-wide. Because exploitation requires a malicious app on the device, audit installed apps, remove unfamiliar or unnecessary ones, and review app permission grants for suspicious data access. Watch for follow-up Apple advisories or a CVSS score, since this flaw landed in a record-setting patch wave and severity details may still be refined.

Affected
Apple iOSversions prior to the fixes in iOS 26.7 and iOS 27
Apple iPadOSversions prior to the fixes in iPadOS 26.7 and iPadOS 27
Apple macOS Sequoiaprior to 15.8
Apple macOS Tahoeprior to 26.7
Apple macOS Golden Gateprior to 27
Apple tvOSprior to 27
Apple visionOSprior to 27
Estimated exposure
massPotentially 1 billion+ Apple devices worldwide running pre-fix OS versions (clearly an estimate) — Apple has publicly reported roughly 2 billion active devices across iPhone, iPad, Mac, Apple TV, and Vision Pro, and every device on an OS version older than the listed fixes is affected until patched, so even partial update lags leave…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A logic issue was addressed with improved validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27. An app may be able to access sensitive user data.

Weakness
CWE-693
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

Apple's record patch cycle fixes 260+ CVEs across iOS 27 and macOS 27, including CUPS remote code execution, with no active exploitation reported.

Apple patched more than 260 CVEs across its operating systems and software, its largest single patch cycle ever, with iOS 27 fixing 122 flaws and macOS 27 Golden Gate fixing 204. Notable bugs include CVE-2026-43692, a CUPS validation issue allowing remote code execution, and CVE-2026-43689, an iOS privilege-escalation flaw granting root access. Ten CVEs were credited to AI-assisted bug hunting, including CVE-2026-65410 and CVE-2026-65409 found by Calif with Claude and Anthropic Research. None of the vulnerabilities are listed as actively exploited.