Description
This issue was addressed with additional entitlement checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, visionOS 27. An app may be able to cause a denial-of-service.
Published: 2026-09-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply patch
AI Analysis

Impact

The flaw originates from missing entitlement checks in Apple Mobile OS, enabling a local application to invoke privileged operations without proper authorization. This can lead to a denial-of-service that disrupts device-wide services and may cause system instability. The weakness is represented by CWE-770 (Uncontrolled Resource Consumption).

Affected Systems

Apple iOS, iPadOS, and visionOS builds prior to iOS 26.7, iPadOS 26.7, and visionOS 27 contain the vulnerability. The fix was released with iOS 26.7, iOS 27, iPadOS 26.7, iPadOS 27, and visionOS 27. Any device running an earlier build could be affected.

Risk and Exploitability

Based on the description, it is inferred that an attacker would need to install a malicious application on the device to trigger the denial-of-service, because the vulnerability is exercised during local app execution. The CVSS score of 5.5 indicates moderate severity with a local requirement for exploitation. The EPSS score of less than 1% suggests a very low probability of exploitation in the operational environment, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the potential for device-wide service interruption can pose tangible risk to environments where device availability is critical.

Generated by OpenCVE AI on September 20, 2026 at 21:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest iOS or iPadOS version (26.7 or newer) or visionOS 27 or newer to incorporate the entitlement check fix
  • Restrict the installation of third‑party applications that are not signed by Apple or are unsigned, to reduce the risk of a malicious app exploiting the vulnerability
  • Monitor device performance for unexpected interruptions or crashes that could indicate exploitation, and investigate incidents promptly

Generated by OpenCVE AI on September 20, 2026 at 21:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Title Denial‑of‑Service via Missing Entitlement Checks in Apple Mobile OS

Sun, 20 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Title Denial of Service from Missing Entitlement Checks in Apple Mobile OS
Weaknesses CWE-284

Fri, 18 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-770
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Title Denial of Service from Missing Entitlement Checks in Apple Mobile OS
Weaknesses CWE-284

Tue, 15 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple visionos
Vendors & Products Apple
Apple ios And Ipados
Apple visionos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description This issue was addressed with additional entitlement checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, visionOS 27. An app may be able to cause a denial-of-service.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Visionos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-17T14:34:46.575Z

Reserved: 2026-09-08T16:43:41.872Z

Link: CVE-2026-86892

cve-icon Vulnrichment

Updated: 2026-09-17T14:34:39.515Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:40.160

Modified: 2026-09-18T14:29:54.027

Link: CVE-2026-86892

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T21:30:06Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling