CVE-2026-65404

Summary

An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A malicious application may be able to bypass Privacy preferences.

Affected Software

VendorProductVersion RangeStatus
AppleiOS and iPadOS0 < 18.7.10affected
AppleiOS and iPadOS0 < 27affected
ApplemacOS0 < 14.8.8affected
ApplemacOS0 < 15.7.8affected
ApplemacOS0 < 27affected

Weaknesses

  • A malicious application may be able to bypass Privacy preferences

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References