Description
A certificate validation issue was addressed with improved certificate validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An attacker with a compromised intermediate certificate authority may be able to issue certificates with arbitrary extended key usages.
Published: 2026-09-14
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Impersonation via forged certificates
Action: Apply Security Update
AI Analysis

Impact

Apple discovered a certificate validation flaw that can allow an attacker who controls a compromised intermediate certificate authority to issue certificates with arbitrary extended key usage values as trusted by Apple operating systems, enabling the attacker to impersonate legitimate services or devices, conduct man‑in‑the‑middle attacks, or bypass integrity checks. Based on the description, it is inferred that the attacker would need access to a compromised intermediate certificate authority to issue the certificates.

Affected Systems

The vulnerability affects Apple iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. All releases prior to the fixes—iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27—remain vulnerable.

Risk and Exploitability

With a CVSS score of 9.1, this flaw is classified as critical severity. The EPSS score of < 1% indicates a very low but non-zero probability of exploitation in the wild. It is not listed in the CISA KEV catalog, so there is no reported active exploitation. An attacker who has control over a compromised intermediate certificate authority can issue certificates with arbitrary extended key usage values and have them trusted by Apple operating systems. Based on the description, it is inferred that the attacker’s only requirement is the ability to generate certificates under a compromised CA, with no additional software or privileged local access needed. This can enable impersonation of legitimate services or devices, man‑in‑the‑middle attacks, or bypass integrity checks.

Generated by OpenCVE AI on September 20, 2026 at 21:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest Apple security updates for iOS, iPadOS, macOS, tvOS, visionOS, and watchOS, which contain the corrected certificate validation logic.
  • If an update cannot be applied immediately, remove or distrust any compromised intermediate certificates from the device’s trust store.
  • Verify key usage values and are issued by trusted, uncompromised authorities; consider disabling extended key usage checks for suspicious certificates.

Generated by OpenCVE AI on September 20, 2026 at 21:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Title Certificate Validation Flaw Enabling Forged Certificate Issuance

Wed, 16 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Wed, 16 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-295
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Title Certificate Validation Flaw Allowing Forged Extended Key Usage by Compromised Intermediate CA
Weaknesses CWE-379

Tue, 15 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
Title Certificate Validation Flaw Allowing Forged Extended Key Usage by Compromised Intermediate CA
Weaknesses CWE-379

Tue, 15 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A certificate validation issue was addressed with improved certificate validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An attacker with a compromised intermediate certificate authority may be able to issue certificates with arbitrary extended key usages.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-16T12:57:12.228Z

Reserved: 2026-09-08T16:43:41.871Z

Link: CVE-2026-86881

cve-icon Vulnrichment

Updated: 2026-09-16T12:56:51.219Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:39.010

Modified: 2026-09-16T18:25:22.767

Link: CVE-2026-86881

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T22:00:09Z

Weaknesses
  • CWE-295

    Improper Certificate Validation