Description
This issue was addressed through improved state management. This issue is fixed in iOS 26.6 and iPadOS 26.6. An attacker with physical access may be able to access sensitive user data during iPhone Mirroring.
Published: 2026-07-27
Score: 4.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper state management flaw in iOS and iPadOS allows an attacker with physical access to capture sensitive user information during iPhone Mirroring sessions, resulting in a confidentiality breach.

Affected Systems

Apple iOS and iPadOS devices running versions prior to 26.6; these versions are affected and the issue is fixed in iOS 26.6 and iPadOS 26.6.

Risk and Exploitability

The vulnerability requires physical proximity to the device and exploits inadequate state handling during mirroring; its exploitation depends on the attacker controlling the device environment, making it a local-attack vector. The EPSS score is lower than 1% (approximately 0.0015) and the vulnerability is not listed in CISA KEV, indicating that it is not known to be actively exploited yet, but the confidentiality risk remains high for users who mirror content.

Generated by OpenCVE AI on August 3, 2026 at 16:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade iOS or iPadOS to version 26.6 or later.
  • Limit or disable iPhone Mirroring when not required to reduce exposure during physical access.
  • Ensure secure physical handling policies, restricting access to trusted personnel and securing the device environment during mirroring sessions.

Generated by OpenCVE AI on August 3, 2026 at 16:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 03 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title Physical Access Can Access Sensitive Data During iPhone Mirroring

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Physical Access Can Access Sensitive Data During iPhone Mirroring
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Vendors & Products Apple
Apple ios And Ipados

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description This issue was addressed through improved state management. This issue is fixed in iOS 26.6 and iPadOS 26.6. An attacker with physical access may be able to access sensitive user data during iPhone Mirroring.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T16:08:12.326Z

Reserved: 2026-07-20T18:09:54.848Z

Link: CVE-2026-64732

cve-icon Vulnrichment

Updated: 2026-07-28T16:08:07.478Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:17:12.130

Modified: 2026-07-28T18:47:51.380

Link: CVE-2026-64732

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T16:30:04Z

Weaknesses