An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS…

cve CVE-2026-86891 1 source, 1 claim · Watch

NVD writes:
An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, watchOS 27. An app may be able to access Bluetooth device information. the claim
Severity
LOW NVD
CVSS
3.5 NVD
Fixed in
15.8, 26.7, 27 NVD
Vendor
Apple NVD
Product
macOS NVD
CWE
CWE-285 NVD

How far exploitation has got

  1. No public code known
  2. Proof of concept
  3. Proof of concept, verified
  4. A Metasploit module
  5. Exploited in the wild
  6. Used in ransomware campaigns

Timeline

2026-09-14first spoke of it: An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, watchOS 27. An app may be able to access Bluetooth device information.NVD

An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, watchOS 27. An app may be able to access Bluetooth device information.

What it is to other things

affectsapple/macos
NVD
affectsapple/watchos
NVD
made_byapple
NVD
Every value, with what each source said and its receipt
PropertySourceSaidMeans here
Automatable
automatable
NVDno
At least one of those steps needs a person.
receipt
Source
NVD
Its words
no
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].automatable
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTCno
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "macOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "15.8",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "26.7",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "watchOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "product-security@apple.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "241A56D1-1E33-4317-A053-85AF8E3770B3",
                "versionEndExcluding": "15.8",
                "versionStartIncluding": "15.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1BE83000-26C0-49C5-A966-BB40AD6F8BEE",
                "versionEndExcluding": "26.7",
                "versionStartIncluding": "26.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "52C964A6-6BF4-4C0A-9C20-FBDE815AE5DF",
                "versionEndExcluding": "27.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, watchOS 27. An app may be able to access Bluetooth device information."
      }
    ],
    "id": "CVE-2026-86891",
    "lastModified": "2026-09-18T14:25:18.230",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "ADJACENT_NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 3.5,
            "baseSeverity": "LOW",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.1,
          "impactScore": 1.4,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-86891",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-17T14:45:08.374606Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-14T21:17:40.067",
    "references": [
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149035"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149037"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149042"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149043"
      }
    ],
    "sourceIdentifier": "product-security@apple.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-285"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS
cvss
NVD3.5
receipt
Source
NVD
Its words
3.5
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.baseScore || field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "macOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "15.8",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "26.7",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "watchOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "product-security@apple.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "241A56D1-1E33-4317-A053-85AF8E3770B3",
                "versionEndExcluding": "15.8",
                "versionStartIncluding": "15.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1BE83000-26C0-49C5-A966-BB40AD6F8BEE",
                "versionEndExcluding": "26.7",
                "versionStartIncluding": "26.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "52C964A6-6BF4-4C0A-9C20-FBDE815AE5DF",
                "versionEndExcluding": "27.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, watchOS 27. An app may be able to access Bluetooth device information."
      }
    ],
    "id": "CVE-2026-86891",
    "lastModified": "2026-09-18T14:25:18.230",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "ADJACENT_NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 3.5,
            "baseSeverity": "LOW",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.1,
          "impactScore": 1.4,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-86891",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-17T14:45:08.374606Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-14T21:17:40.067",
    "references": [
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149035"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149037"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149042"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149043"
      }
    ],
    "sourceIdentifier": "product-security@apple.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-285"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS vector
cvss_vector
NVDCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
receipt
Source
NVD
Its words
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.vectorString || field:cve.metrics.cvssMetricV31[].cvssData.vectorString
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTCCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "macOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "15.8",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "26.7",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "watchOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "product-security@apple.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "241A56D1-1E33-4317-A053-85AF8E3770B3",
                "versionEndExcluding": "15.8",
                "versionStartIncluding": "15.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1BE83000-26C0-49C5-A966-BB40AD6F8BEE",
                "versionEndExcluding": "26.7",
                "versionStartIncluding": "26.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "52C964A6-6BF4-4C0A-9C20-FBDE815AE5DF",
                "versionEndExcluding": "27.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, watchOS 27. An app may be able to access Bluetooth device information."
      }
    ],
    "id": "CVE-2026-86891",
    "lastModified": "2026-09-18T14:25:18.230",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "ADJACENT_NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 3.5,
            "baseSeverity": "LOW",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.1,
          "impactScore": 1.4,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-86891",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-17T14:45:08.374606Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-14T21:17:40.067",
    "references": [
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149035"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149037"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149042"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149043"
      }
    ],
    "sourceIdentifier": "product-security@apple.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-285"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
CWE
cwe
NVDCWE-285
receipt
Source
NVD
Its words
CWE-285
Read by
field:cve.weaknesses[].description[].value
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTCCWE-285
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "macOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "15.8",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "26.7",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "watchOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "product-security@apple.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "241A56D1-1E33-4317-A053-85AF8E3770B3",
                "versionEndExcluding": "15.8",
                "versionStartIncluding": "15.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1BE83000-26C0-49C5-A966-BB40AD6F8BEE",
                "versionEndExcluding": "26.7",
                "versionStartIncluding": "26.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "52C964A6-6BF4-4C0A-9C20-FBDE815AE5DF",
                "versionEndExcluding": "27.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, watchOS 27. An app may be able to access Bluetooth device information."
      }
    ],
    "id": "CVE-2026-86891",
    "lastModified": "2026-09-18T14:25:18.230",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "ADJACENT_NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 3.5,
            "baseSeverity": "LOW",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.1,
          "impactScore": 1.4,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-86891",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-17T14:45:08.374606Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-14T21:17:40.067",
    "references": [
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149035"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149037"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149042"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149043"
      }
    ],
    "sourceIdentifier": "product-security@apple.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-285"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Exploitation
exploitation
NVDnone
No evidence of exploitation, and no public proof of concept.
receipt
Source
NVD
Its words
none
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].exploitation
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTCnone
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "macOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "15.8",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "26.7",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "watchOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "product-security@apple.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "241A56D1-1E33-4317-A053-85AF8E3770B3",
                "versionEndExcluding": "15.8",
                "versionStartIncluding": "15.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1BE83000-26C0-49C5-A966-BB40AD6F8BEE",
                "versionEndExcluding": "26.7",
                "versionStartIncluding": "26.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "52C964A6-6BF4-4C0A-9C20-FBDE815AE5DF",
                "versionEndExcluding": "27.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, watchOS 27. An app may be able to access Bluetooth device information."
      }
    ],
    "id": "CVE-2026-86891",
    "lastModified": "2026-09-18T14:25:18.230",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "ADJACENT_NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 3.5,
            "baseSeverity": "LOW",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.1,
          "impactScore": 1.4,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-86891",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-17T14:45:08.374606Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-14T21:17:40.067",
    "references": [
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149035"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149037"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149042"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149043"
      }
    ],
    "sourceIdentifier": "product-security@apple.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-285"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Fixed in
fixed_in
NVD15.8, 26.7, 27
receipt
Source
NVD
Its words
15.8, 26.7, 27
Read by
field:cve.affected[].affectedData[].versions[status=affected].lessThan
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTC15.8, 26.7, 27
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "macOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "15.8",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "26.7",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "watchOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "product-security@apple.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "241A56D1-1E33-4317-A053-85AF8E3770B3",
                "versionEndExcluding": "15.8",
                "versionStartIncluding": "15.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1BE83000-26C0-49C5-A966-BB40AD6F8BEE",
                "versionEndExcluding": "26.7",
                "versionStartIncluding": "26.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "52C964A6-6BF4-4C0A-9C20-FBDE815AE5DF",
                "versionEndExcluding": "27.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, watchOS 27. An app may be able to access Bluetooth device information."
      }
    ],
    "id": "CVE-2026-86891",
    "lastModified": "2026-09-18T14:25:18.230",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "ADJACENT_NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 3.5,
            "baseSeverity": "LOW",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.1,
          "impactScore": 1.4,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-86891",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-17T14:45:08.374606Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-14T21:17:40.067",
    "references": [
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149035"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149037"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149042"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149043"
      }
    ],
    "sourceIdentifier": "product-security@apple.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-285"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Product
product
NVDmacOS
receipt
Source
NVD
Its words
macOS
Read by
field:cve.affected[].affectedData[].product
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-09-29 17:49 UTCmacOS
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "macOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "15.8",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "26.7",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "watchOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "product-security@apple.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "241A56D1-1E33-4317-A053-85AF8E3770B3",
                "versionEndExcluding": "15.8",
                "versionStartIncluding": "15.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1BE83000-26C0-49C5-A966-BB40AD6F8BEE",
                "versionEndExcluding": "26.7",
                "versionStartIncluding": "26.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "52C964A6-6BF4-4C0A-9C20-FBDE815AE5DF",
                "versionEndExcluding": "27.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, watchOS 27. An app may be able to access Bluetooth device information."
      }
    ],
    "id": "CVE-2026-86891",
    "lastModified": "2026-09-18T14:25:18.230",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "ADJACENT_NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 3.5,
            "baseSeverity": "LOW",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.1,
          "impactScore": 1.4,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-86891",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-17T14:45:08.374606Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-14T21:17:40.067",
    "references": [
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149035"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149037"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149042"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149043"
      }
    ],
    "sourceIdentifier": "product-security@apple.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-285"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Severity
severity
NVDLOW
From 0.1 to 3.9.
receipt
Source
NVD
Its words
LOW
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.baseSeverity || field:cve.metrics.cvssMetricV31[].cvssData.baseSeverity
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTCLOW
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "macOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "15.8",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "26.7",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "watchOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "product-security@apple.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "241A56D1-1E33-4317-A053-85AF8E3770B3",
                "versionEndExcluding": "15.8",
                "versionStartIncluding": "15.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1BE83000-26C0-49C5-A966-BB40AD6F8BEE",
                "versionEndExcluding": "26.7",
                "versionStartIncluding": "26.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "52C964A6-6BF4-4C0A-9C20-FBDE815AE5DF",
                "versionEndExcluding": "27.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, watchOS 27. An app may be able to access Bluetooth device information."
      }
    ],
    "id": "CVE-2026-86891",
    "lastModified": "2026-09-18T14:25:18.230",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "ADJACENT_NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 3.5,
            "baseSeverity": "LOW",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.1,
          "impactScore": 1.4,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-86891",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-17T14:45:08.374606Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-14T21:17:40.067",
    "references": [
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149035"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149037"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149042"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149043"
      }
    ],
    "sourceIdentifier": "product-security@apple.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-285"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
low
Status
status
NVDAnalyzed
receipt
Source
NVD
Its words
Analyzed
Read by
field:cve.vulnStatus
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "macOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "15.8",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "26.7",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "watchOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "product-security@apple.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "241A56D1-1E33-4317-A053-85AF8E3770B3",
                "versionEndExcluding": "15.8",
                "versionStartIncluding": "15.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1BE83000-26C0-49C5-A966-BB40AD6F8BEE",
                "versionEndExcluding": "26.7",
                "versionStartIncluding": "26.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "52C964A6-6BF4-4C0A-9C20-FBDE815AE5DF",
                "versionEndExcluding": "27.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, watchOS 27. An app may be able to access Bluetooth device information."
      }
    ],
    "id": "CVE-2026-86891",
    "lastModified": "2026-09-18T14:25:18.230",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "ADJACENT_NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 3.5,
            "baseSeverity": "LOW",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.1,
          "impactScore": 1.4,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-86891",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-17T14:45:08.374606Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-14T21:17:40.067",
    "references": [
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149035"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149037"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149042"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149043"
      }
    ],
    "sourceIdentifier": "product-security@apple.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-285"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Technical impact
technical_impact
NVDpartial
The attacker gains limited control, or limited information.
receipt
Source
NVD
Its words
partial
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].technicalImpact
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTCpartial
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "macOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "15.8",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "26.7",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "watchOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "product-security@apple.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "241A56D1-1E33-4317-A053-85AF8E3770B3",
                "versionEndExcluding": "15.8",
                "versionStartIncluding": "15.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1BE83000-26C0-49C5-A966-BB40AD6F8BEE",
                "versionEndExcluding": "26.7",
                "versionStartIncluding": "26.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "52C964A6-6BF4-4C0A-9C20-FBDE815AE5DF",
                "versionEndExcluding": "27.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, watchOS 27. An app may be able to access Bluetooth device information."
      }
    ],
    "id": "CVE-2026-86891",
    "lastModified": "2026-09-18T14:25:18.230",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "ADJACENT_NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 3.5,
            "baseSeverity": "LOW",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.1,
          "impactScore": 1.4,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-86891",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-17T14:45:08.374606Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-14T21:17:40.067",
    "references": [
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149035"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149037"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149042"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149043"
      }
    ],
    "sourceIdentifier": "product-security@apple.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-285"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Vendor
vendor
NVDApple
receipt
Source
NVD
Its words
Apple
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-09-29 17:49 UTCApple
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "macOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "15.8",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "26.7",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "watchOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "product-security@apple.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "241A56D1-1E33-4317-A053-85AF8E3770B3",
                "versionEndExcluding": "15.8",
                "versionStartIncluding": "15.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1BE83000-26C0-49C5-A966-BB40AD6F8BEE",
                "versionEndExcluding": "26.7",
                "versionStartIncluding": "26.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "52C964A6-6BF4-4C0A-9C20-FBDE815AE5DF",
                "versionEndExcluding": "27.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, watchOS 27. An app may be able to access Bluetooth device information."
      }
    ],
    "id": "CVE-2026-86891",
    "lastModified": "2026-09-18T14:25:18.230",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "ADJACENT_NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 3.5,
            "baseSeverity": "LOW",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.1,
          "impactScore": 1.4,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-86891",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-17T14:45:08.374606Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-14T21:17:40.067",
    "references": [
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149035"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149037"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149042"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/149043"
      }
    ],
    "sourceIdentifier": "product-security@apple.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-285"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Every claim, by kind

vulnerability

An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, watchOS 27. An app may be able to access Bluetooth device information.
zetlyn/cve-nvd · 2026-09-14
automatable no cvss 3.5 cvss_vector CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N cwe CWE-285 exploitation none fixed_in 15.8, 26.7, 27 product macOS severity LOW status Analyzed technical_impact partial vendor Apple source