Authorization Flaw in Apple Products Allows Motion Data Access
CVE-2026-43737

Currently unrated

Key Information:

Vendor

Apple

Vendor
CVE Published:
14 September 2026

What is CVE-2026-43737?

A significant authorization vulnerability has been identified in various Apple operating systems that could allow unauthorized applications to access motion data from connected headphones without the user's explicit consent. This flaw highlights the importance of stringent validation processes to safeguard user privacy. The issue has been addressed with improved validation mechanisms in recent updates, ensuring enhanced security across affected devices.

Affected Version(s)

iOS and iPadOS 0 < 26.7

iOS and iPadOS 0 < 27

macOS 0 < 15.8

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.