Description
An authentication issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27. An attacker with physical access to an unlocked device may be able to view Wi-Fi passwords without authentication.
Published: 2026-09-14
Score: 4.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure of Wi‑Fi passwords
Action: Update OS
AI Analysis

Impact

The vulnerability is a flaw in the operating system’s state management that allows an attacker with physical access to a device that is currently unlocked to view stored Wi‑Fi passwords without any authentication or authorization. Once the device is unlocked, the defect bypasses normal credential checks and exposes sensitive network credentials, which could enable the attacker to connect to, spoof, or misuse wireless networks.

Affected Systems

Apple devices running iOS or iPadOS prior to version 27 are affected. The fix is included in iOS 27 and iPadOS 27, so any device on an earlier release is potentially vulnerable.

Risk and Exploitability

The attack requires physical possession of an unlocked device, so it is a local, limited‑scope vulnerability. The EPSS score indicates a low but nonzero exploitation probability of less than 1%, and the issue is not listed in CISA's KEV. Updating to the patched OS or ensuring the device remains locked before use mitigates the risk.

Generated by OpenCVE AI on September 20, 2026 at 19:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to iOS 27 or iPadOS 27 to apply the state‑management fix
  • Keep the device locked whenever it is unattended to prevent unauthorized access
  • Change Wi‑Fi passwords promptly after an upgrade to ensure stored credentials are fresh and prevent credential reuse

Generated by OpenCVE AI on September 20, 2026 at 19:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Fri, 18 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
Metrics cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Title Wireless Password Disclosure via State Management Issue on Unlocked Devices
Weaknesses CWE-200
CWE-287

Tue, 15 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Title Wireless Password Disclosure via State Management Issue on Unlocked Devices
Weaknesses CWE-200
CWE-287

Tue, 15 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Vendors & Products Apple
Apple ios And Ipados

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description An authentication issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27. An attacker with physical access to an unlocked device may be able to view Wi-Fi passwords without authentication.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-17T16:14:10.915Z

Reserved: 2026-05-01T22:46:21.640Z

Link: CVE-2026-43674

cve-icon Vulnrichment

Updated: 2026-09-17T16:14:04.223Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:06.900

Modified: 2026-09-18T14:41:20.700

Link: CVE-2026-43674

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T19:30:04Z

Weaknesses