Impact
An authenticationOS permits attackers with privileged network access to undermine IPSec authentication, enabling them to intercept data traversing secure tunnels. The flaw stems from improper state management that was mitigated in iOS and iPadOS 26.6.1 and later releases. Because legitimate authentication checks can be bypassed, the vulnerability jeopardizes the confidentiality and integrity of traffic routed through IPSec.
Affected Systems
Apple iOS and iPadOS devices that run versions prior to 26.6.1 are affected. The flaw is fixed in iOS 26.6.1, so any device with an older OS revision remains vulnerable.
Risk and Exploitability
The EPSS score is <1%, and the CVSS score is 5.9, indicating a moderate severity vulnerability. The flaw is not listed in the CISA KEV catalog, suggesting no confirmed exploitation. Because an attacker must be in a privileged network position, the risk remains significant for internal or compromised networks using IPSec tunnels. No additional prerequisites are listed, so the vulnerability appears exploitable in any environment where IPSec authentication can be manipulated.
OpenCVE Enrichment