Description
A logic issue was addressed with improved checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27. An attacker with physical access to a locked device may be able to view sensitive user information.
Published: 2026-09-14
Score: 4.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Data Exposure on Locked Devices
Action: Immediate Patch
AI Analysis

Impact

A logic bug was identified in iOS and iPadOS that was addressed with additional checks in later releases. The issue allows an attacker who has physical access to a locked device to view sensitive user information. This vulnerability directly impacts the confidentiality of user data and can lead to a loss of privacy when an adversary is in physical proximity to the device.

Affected Systems

The vulnerability affects Apple iOS and iPadOS devices running versions older than iOS 26.7 and iPadOS 26.7, and older than iOS 27 and iPadOS 27. Any device before the 26.7/27 releases is considered affected; recent releases implement the corrective checks intended to prevent this oversight.

Risk and Exploitability

The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploitation. However, the attack requires only physical access to a locked device, which is a low‑barrier vector for motivated attackers. Because the flaw results in information disclosure, its potential impact on confidentiality is high. Until the device firmware is updated, an adversary with physical control can exploit this weak logic to read protected data. The fix is available in iOS 26.7/iPadOS 26.7 and iOS 27/iPadOS 27.

Generated by OpenCVE AI on September 20, 2026 at 22:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade all affected iOS and iPadOS devices to version 26.7 or later, and to version 27 or later when available.
  • Ensure devices are physically secured, preventing unauthorized access by lockable media or door controls.
  • Enforce strong passcode policies and enable full‑disk encryption to reduce the window in which the logic flaw can be exploited.

Generated by OpenCVE AI on September 20, 2026 at 22:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
Title Locked Apple Devices Allow Sensitive Data Exposure with Physical Access

Sun, 20 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Sensitive Data Exposure via Physical Access on Locked iOS/iPadOS Devices
Weaknesses CWE-284

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
Metrics cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Title Sensitive Data Exposure via Physical Access on Locked iOS/iPadOS Devices
Weaknesses CWE-284

Tue, 15 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Vendors & Products Apple
Apple ios And Ipados

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A logic issue was addressed with improved checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27. An attacker with physical access to a locked device may be able to view sensitive user information.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-16T15:21:10.985Z

Reserved: 2026-09-08T16:43:41.872Z

Link: CVE-2026-86890

cve-icon Vulnrichment

Updated: 2026-09-16T15:20:39.756Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:39.963

Modified: 2026-09-16T17:10:57.853

Link: CVE-2026-86890

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T22:45:05Z

Weaknesses