Sensitive Data Exposure in Apple Safari and iOS Products
CVE-2026-86897

5.5MEDIUM

Key Information:

Vendor

Apple

Vendor
CVE Published:
14 September 2026

What is CVE-2026-86897?

An issue has been identified in Apple's Safari and operating systems that could allow apps to access sensitive user data without proper entitlements. This vulnerability has been addressed in the latest updates for Safari, iOS, iPadOS, macOS, and visionOS by implementing additional entitlement checks, which enhance the security measures against unauthorized data access.

Affected Version(s)

iOS and iPadOS 0 < 26.7

iOS and iPadOS 0 < 27

macOS 0 < 27

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.