We've configured "Issue Security" in Jira Cloud, so some issues are only visible to the "Administrator" role.
If you check through the UI, everything works correctly; users with other roles don't see the issue.
However, when using the API (https://developer.atlassian.com/cloud/jira/platform/rest/v3/api-group-user-search/#api-rest-api-3-user-viewissue-search-get), the "Find users with browse permission" section specifies "returns only the users from that range that match the search string and have permission to browse issues."
However, in our case, when calling the API, users are returned even if they don't have access to a specific issue.