SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-84628

MEDIUM · CVSS 5.5 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A vulnerability exists in unspecified products that allows a sandboxed application to potentially access the System Keychain due to an authorization issue related to state management. This could lead to unauthorized access to sensitive information stored in the keychain, posing a significant risk to user data security. Developers and organizations utilizing affected Apple operating systems, particularly those managing sensitive information, should prioritize applying the updates available in iOS 27, iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, and watchOS 27.

CVE
CVE-2026-84628
Severity
MEDIUM
CVSS
5.5
EPSS
0.16%

Original NVD Description

An authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. A sandboxed app may be able to access the System Keychain.