Sceawere
Vulnerability Detail
CVE-2026-43679UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
watchOS Contact Information Disclosure Vulnerability
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 2.4
- Creation Date
- 16h ago
- Vendor
- Apple
- Product
- watchOS
- Attack Type
- An attacker with physical access to a locked Apple Watch may be able to view user contacts
- Vector String
- CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
This issue was addressed with improved permissions checking. This issue is fixed in watchOS 26.4. An attacker with physical access to a locked Apple Watch may be able to view user contacts.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "2.4",
"pubDate": "2026-08-21T01:17:01.723Z",
"pubdate": "2026-08-21T01:17:01.723Z",
"executiveSummary": "An information disclosure vulnerability has been identified in watchOS, specifically involving unauthorized access to sensitive user data on locked devices.\nThe vulnerability allows an adversary to view user contacts while the Apple Watch is in a locked state, bypassing expected authentication boundaries.\nThe affected product is watchOS, and the issue is resolved in watchOS 26.4.\nThe primary risk implication is the compromise of personal privacy and sensitive user information stored locally on the device.\nThe required attacker capability is physical access to the target Apple Watch.\nNo remote exploitation vectors are indicated; the attack strictly requires immediate physical proximity and interaction with the locked hardware.",
"technicalDetails": "The root cause of the vulnerability stems from insufficient permissions checking within the operating system's access control mechanisms for contact data.\nThe vulnerable component fails to adequately validate the device lock state and associated authorization contexts before rendering sensitive user contacts to the interface.\nPrivilege and authentication requirements are bypassed due to this logic flaw, enabling unauthorized read operations on contact data despite the device being locked.\nThe attack flow requires the threat actor to obtain physical access to the target Apple Watch while it is in a locked state.\nUpon acquiring physical access, the attacker interacts with the device's user interface or underlying system subsystems that improperly enforce security boundaries.\nBecause the permissions checking logic lacks strict validation against the lock state, the system improperly permits the retrieval and rendering of user contacts.\nThe post-exploitation impact is limited to unauthorized information disclosure, specifically the exposure of personal contact lists and associated metadata stored on the device.\nThe vulnerability is remediated in watchOS 26.4 through the implementation of improved permissions checking and enhanced authorization validation workflows."
}