CVE-2026-86890

A logic issue was addressed with improved checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27. An attacker with physical access to a locked device may be able to view sensitive user information.
References
Link Resource
https://support.apple.com/en-us/149034 Vendor Advisory Release Notes
https://support.apple.com/en-us/149041 Vendor Advisory Release Notes
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*

History

16 Sep 2026, 17:10

Type Values Removed Values Added
First Time Apple iphone Os
Apple ipados
Apple
CPE cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
References () https://support.apple.com/en-us/149034 - () https://support.apple.com/en-us/149034 - Vendor Advisory, Release Notes
References () https://support.apple.com/en-us/149041 - () https://support.apple.com/en-us/149041 - Vendor Advisory, Release Notes

16 Sep 2026, 16:17

Type Values Removed Values Added
CWE CWE-287
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.6

Information

Published : 2026-09-14 21:17

Updated : 2026-09-16 17:10


NVD link : CVE-2026-86890

Mitre link : CVE-2026-86890

CVE.ORG link : CVE-2026-86890


JSON object : View

Products Affected

apple

  • ipados
  • iphone_os
CWE
CWE-287

Improper Authentication