Description
This issue was addressed with additional entitlement checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, visionOS 27. An app may be able to cause a denial-of-service.
Published: 2026-09-14
Score: n/a
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Patch immediately
AI Analysis

Impact

An app can trigger a denial‑ checks that should restrict certain OS functions. The flaw allows any application that has obtained general installation rights to send requests that overwhelm or crash target system threads, leading to a disruption of device functionality. The impact is limited to service interruption and does not disclose or modify data.

Affected Systems

Apple iOS versions prior to 26.7, iPadOS versions prior to 26.7, and visionOS versions prior to 27 are affected. The issue was resolved in iOS 26.7 and 27, iPadOS 26.7 and 27, and visionOS 27, so any device running an older build could potentially be compromised.

Risk and Exploitability

The vulnerability is exploitable from within a local application context; an attacker would need to install a malicious app on the device. No EPSS or KEV data is available, and the CVSS score is not disclosed, but because the flaw permits a device‑wide DoS, the risk is tangible for environments where device availability is critical. The attack path requires only user‑level privileges granted by the OS to the app, so no elevated permissions are needed.

Generated by OpenCVE AI on September 15, 2026 at 08:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest iOS or iPadOS version (26.7 or newer) or visionOS 27 or newer to apply the entitlement check fix
  • Remove or restrict installation of untrusted third‑party applications that could exploit the entitlement flaw
  • Monitor device stability and app behavior for sudden crashes or resource exhaustion that could indicate use of the flaw

Generated by OpenCVE AI on September 15, 2026 at 08:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Title Denial of Service from Missing Entitlement Checks in Apple Mobile OS
Weaknesses CWE-284

Tue, 15 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple visionos
Vendors & Products Apple
Apple ios And Ipados
Apple visionos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description This issue was addressed with additional entitlement checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, visionOS 27. An app may be able to cause a denial-of-service.
References

Subscriptions

Apple Ios And Ipados Visionos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-14T20:49:48.092Z

Reserved: 2026-09-08T16:43:41.872Z

Link: CVE-2026-86892

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-14T21:17:40.160

Modified: 2026-09-14T21:17:40.160

Link: CVE-2026-86892

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T08:15:13Z

Weaknesses