About the security content of iOS 27 and iPadOS 27

This document describes the security content of iOS 27 and iPadOS 27.

About Apple security updates

For our customers' protection, Apple doesn't disclose, discuss, or confirm security issues until an investigation has occurred and patches or releases are available. Recent releases are listed on the Apple security releases page.

Apple security documents reference vulnerabilities by CVE-ID when possible.

For more information about security, see the Apple Product Security page.

iOS 27 and iPadOS 27

Released September 14, 2026

Accelerate Framework

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: Processing a maliciously crafted image may lead to unexpected process termination

Description: An out-of-bounds write issue was addressed with improved bounds checking.

CVE-2026-86882: Peter Malone

Accessibility

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to access sensitive user data

Description: This issue was addressed with improved data protection.

CVE-2026-43664: Stuart Wallace, Ilya Andr (andrd3v), Rosyna Keller of Totally Not Malicious Software, CJ Vana, David Strnadel, Daniel Febrero, Asaf Cohen, Gongyu Ma (@Mezone0), Jian Lee (@speedyfriend433)

Accessibility

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to identify what other apps a user has installed

Description: A privacy issue was addressed with improved handling of user preferences.

CVE-2026-64761: Stuart Wallace, Sindre Sorhus

Accounts

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: A malicious application may be able to bypass Privacy preferences

Description: An authorization issue was addressed with improved state management.

CVE-2026-65404: Arni Hardarson (Neonix Security), Vinay Kumar Rasala (Xplo8E) from Appknox, Stuart Wallace, 이재영

APFS

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to cause unexpected system termination or write kernel memory

Description: An out-of-bounds write issue was addressed with improved bounds checking.

CVE-2026-84523: Cem Onat Karagun, an anonymous researcher

App Store

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: A local app may be able to read a persistent account identifier

Description: A permissions issue was addressed with additional restrictions.

CVE-2026-86888: Zhongcheng Li (CK01)

Apple Account

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to use the Sign In With Apple authentication flow to access the user's Apple Account

Description: An authentication issue was addressed with improved state management.

CVE-2026-20683: Dem0ns (@天府简易信工作室), Abdelhak Kherroubi, Jasminder Pal Singh, Lehan Dilusha Jayasingha (Sri Lanka)

Apple Neural Engine

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to cause unexpected system termination

Description: An integer overflow was addressed with improved input validation.

CVE-2026-65408: tamdao

AppleAVD

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to cause unexpected system termination

Description: A use after free issue was addressed with improved memory management.

CVE-2026-65407: Franco Belman at Blackwing Intelligence

AppleDouble

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: Mounting a disk image with maliciously crafted files may lead to unexpected system termination

Description: An out-of-bounds write issue was addressed with improved bounds checking.

CVE-2026-84519: Richard Zana

AppleKeyStore

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to cause unexpected system termination

Description: A use after free issue was addressed with improved memory management.

CVE-2026-84593: Meta Red Team X - Nik Tsytsarkin, Alexandre Borges

Authentication Services

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to delete credentials stored in Keychain

Description: This issue was addressed by removing the vulnerable code.

CVE-2026-86905: Ilya Andr (andrd3v)

AuthKit

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: A local app may be able to read a persistent account identifier

Description: A permissions issue was addressed with additional restrictions.

CVE-2026-84583: Zhongcheng Li from IES Red Team

AVEVideoEncoder

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to cause unexpected system termination

Description: The issue was addressed with improved checks.

CVE-2026-65410: Calif.io in collaboration with Claude and Anthropic Research

AVEVideoEncoder

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to cause unexpected system termination

Description: A type confusion issue was addressed with improved memory handling.

CVE-2026-84616: Peter Malone

AVEVideoEncoder

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: A sandboxed app may be able to execute arbitrary code with kernel privileges

Description: A race condition was addressed with improved state management.

CVE-2026-84607: Ruslan Dautov

BackgroundAssets

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to access sensitive user data

Description: A logic issue was addressed with improved validation.

CVE-2026-65406: Ye Zhang (@VAR10CK) of Baidu Security

Baseband

Available for: iPhone 11 and later

Impact: An attacker in radio range may be able to cause unexpected system termination

Description: An input validation issue was addressed with improved input validation.

CVE-2026-86885: Tuan D. Hoang, Hazem Issa, and Yongdae Kim @ KAIST SysSec Lab

Baseband

Available for: iPhone 11 and later

Impact: A remote attacker may be able to cause a denial-of-service

Description: A denial-of-service issue was addressed with improved input validation.

CVE-2026-86879: Hazem Issa and Yongdae Kim @ SysSec, KAIST

Bluetooth

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: A remote attacker may be able to cause unexpected app termination or arbitrary code execution

Description: An out-of-bounds write issue was addressed with improved bounds checking.

CVE-2026-65414

Bluetooth

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may gain unauthorized access to Bluetooth

Description: An authorization issue was addressed with improved state management.

CVE-2026-84560: an anonymous researcher

Camera

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to access sensitive user data

Description: A permissions issue was addressed with additional restrictions.

CVE-2026-86878: Sindre Sorhus, Ilya Andr (andrd3v) of Positive Technologies, Asaf Cohen

CloudKit

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: A local app may be able to read a persistent account identifier

Description: An information disclosure issue was addressed with improved state management.

CVE-2026-86895: Stanislav Jelezoglo

CloudKit

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to read device name

Description: A permissions issue was addressed with additional restrictions.

CVE-2026-86893: Heiner Gerdes

copyfile

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An archive may be able to bypass Gatekeeper

Description: A file quarantine bypass was addressed with additional checks.

CVE-2026-65399: Rishabh Jain (rjcyber) of cyberplanet, Pasquale Scola, an anonymous researcher

CoreMedia

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: Processing a maliciously crafted image may lead to arbitrary code execution

Description: A memory corruption issue was addressed by removing the vulnerable code.

CVE-2026-64752: Nik Tsytsarkin

CoreMedia

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: A sandboxed process may be able to circumvent sandbox restrictions

Description: An out-of-bounds write issue was addressed with improved bounds checking.

CVE-2026-86876: Chris Bailey - Short Circuit

CoreMedia

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: Processing a maliciously crafted video file may lead to unexpected app termination

Description: An out-of-bounds write issue was addressed with improved bounds checking.

CVE-2026-65344: Siyeong kim

CoreML

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: A sandboxed app may be able to access restricted files

Description: A permissions issue was addressed with improved path validation.

CVE-2026-84624: AL Najafi, tamdao

CoreMotion

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to access motion data from headphones without user consent

Description: An authorization issue was addressed with improved validation.

CVE-2026-43737: Stuart Wallace

CoreText

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: Processing web content may lead to a denial-of-service

Description: A null pointer dereference was addressed with improved input validation.

CVE-2026-65412: Pavan Nallamothu

CoreText

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: Processing a maliciously crafted font may result in the disclosure of process memory

Description: An out-of-bounds read was addressed with improved bounds checking.

CVE-2026-84596: ret2happy, Meta Product Security

CoreUI

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: Processing a maliciously crafted file may lead to unexpected app termination

Description: An out-of-bounds write issue was addressed with improved bounds checking.

CVE-2026-84575: Mustafa Calap (@ordinal0, dbg.re)

CoreUI

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to cause a denial of service

Description: A buffer overflow was addressed with improved bounds checking.

CVE-2026-84489: stratan (@5tratan), Peter Malone

CoreUI

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: Processing a maliciously crafted image may lead to unexpected app termination

Description: A buffer overflow was addressed with improved bounds checking.

CVE-2026-84571: stratan (@5tratan), Peter Malone

CoreUI

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: Processing a maliciously crafted asset catalog may result in disclosure of process memory

Description: The issue was addressed with improved memory handling.

CVE-2026-43738: Peter Malone

CoreUI

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: Processing a maliciously crafted asset catalog may lead to unexpected process termination

Description: An out-of-bounds write issue was addressed with improved bounds checking.

CVE-2026-84511: Rahul Raj, stratan (@5tratan)

DeviceCheck

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to read persistent device identifiers

Description: An authorization issue was addressed with improved access control.

CVE-2026-84612: N.M.Praveen Nawarathne (@zblockrat), James Gill (@jjtech@infosec.exchange)

Disk Images

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to cause unexpected system termination

Description: The issue was addressed with improved memory handling.

CVE-2026-84552: Tommy DeVoss from Braze Security Team (@thedawgyg), flower xu, Adriatik Raci, PETOWORKS의 Bugeun Choi (@Bugeun), Peter Malone, Daisuke Hatakeyama and Ryohei Ueki (@SYZD Research), Hyunwoo Kim (@v4bel)

exFAT

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: Mounting a maliciously crafted volume may lead to unexpected system termination

Description: A heap buffer overflow was addressed with improved bounds checking.

CVE-2026-84510: Meta Red Team X - Nik Tsytsarkin, Richard Zana

File Bookmark

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to modify a file it only had permission to read

Description: A permissions issue was addressed with additional restrictions.

CVE-2026-43785: Junyeong Lee (jylab.github.io), Merrick Hare, Aditya Kumar, John Nzyuko Uvyu, Narendra Singh (@_3P1C)

file_cmds

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: Extracting a maliciously crafted archive may allow an attacker to write arbitrary files

Description: A path handling issue was addressed with improved validation.

CVE-2026-84534: Geoffrey Lovelace

Filters

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: Processing a maliciously crafted file may lead to unexpected app termination

Description: A memory corruption issue was addressed with improved input validation.

CVE-2026-43688: Peter Malone

FontParser

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: Processing a maliciously crafted font file may lead to unexpected app termination

Description: An out-of-bounds read was addressed with improved bounds checking.

CVE-2026-84524: an anonymous researcher

FontParser

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: Processing a maliciously crafted font may result in the disclosure of process memory

Description: An out-of-bounds read issue was addressed with improved input validation.

CVE-2026-84597: Nik Tsytsarkin

Foundation

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to cause a denial of service

Description: A type confusion issue was addressed with improved memory handling.

CVE-2026-65409: Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research

Graphics

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to cause unexpected system termination

Description: A race condition was addressed with improved state handling.

CVE-2026-84492: Tommy DeVoss from Braze Security Team (@thedawgyg), Jiyong Yang

Heimdal

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An attacker in a privileged network position may be able to modify network traffic

Description: A cryptographic issue was addressed with improved integrity checks.

CVE-2026-84533: Vishal Patidar, Roman Zabicki

iCloud

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to identify a user across reinstalls

Description: A privacy issue was addressed with improved handling of identifiers.

CVE-2026-84606: Ilya Andr (andrd3v)

Image Capture

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to access user-sensitive data

Description: A path handling issue was addressed with improved validation.

CVE-2026-64756: Luke Symons

ImageIO

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: Processing a maliciously crafted image may result in disclosure of process memory

Description: An uninitialized memory issue was addressed with improved memory initialization.

CVE-2026-84564: Justin O'Leary

ImageIO

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: Processing a maliciously crafted image may result in memory corruption

Description: An out-of-bounds write issue was addressed with improved bounds checking.

CVE-2026-65395: Mateusz Jurczyk of Google Project Zero, Varik Matevosyan

IOKit

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to cause unexpected system termination

Description: A use after free issue was addressed with improved memory management.

CVE-2026-28969: Mihalis Haatainen, Ashish Kunwar, Ari Hawking, 이재영

IOMobileFrameBuffer

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to cause unexpected system termination or corrupt kernel memory

Description: An out-of-bounds access issue was addressed with improved bounds checking.

CVE-2026-65398: Chris Bailey - Short Circuit, Mustafa Calap (@ordinal0, dbg.re), David Strnadel, Meta Red Team X - Nik Tsytsarkin

IOSurfaceAccelerator

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to leak sensitive kernel state

Description: An information leakage was addressed with additional validation.

CVE-2026-64760: an anonymous researcher, Seiji Sakurai (@HeapSmasher), Franco Belman at Blackwing Intelligence

iWork

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: A malicious app may be able to break out of its sandbox

Description: A permissions issue was addressed with additional restrictions.

CVE-2026-65354: Csaba Fitzl (@theevilbit) of Iru

Kernel

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to cause unexpected system termination or corrupt kernel memory

Description: An out-of-bounds write issue was addressed with improved bounds checking.

CVE-2026-28968: genter0, Svetoslav Stolarov & Aisa Fox, Josh Maine of Calif.io, Dun

Kernel

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: A local attacker may be able to cause unexpected system termination or corrupt kernel memory

Description: The issue was addressed with improved memory handling.

CVE-2026-84566: Bernhard Jackiewicz

Kernel

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: A local user may be able to cause unexpected system termination or read kernel memory

Description: A race condition was addressed with additional validation.

CVE-2026-65415: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd., Ryan Hileman via Xint Code (xint.io)

Kernel

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to cause unexpected system termination or corrupt kernel memory

Description: A double free issue was addressed with improved memory management.

CVE-2026-84561: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd., Bhaswanth Chigurupati

Kernel

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to cause unexpected system termination

Description: A race condition was addressed with improved state handling.

CVE-2026-84630: Tristan Madani (@TristanInSec) from Talence Security

CVE-2026-65360: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.

CVE-2026-65358: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.

Kernel

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to cause unexpected system termination

Description: A memory corruption issue was addressed with improved memory handling.

CVE-2026-65377: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd., Ye Zhang (@VAR10CK) of Baidu Security

Kernel

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app with root privileges may be able to read uninitialized kernel memory

Description: A memory initialization issue was addressed with improved memory handling.

CVE-2026-84622: Hiroki Imai (LAC Co., Ltd.)

Kernel

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: A malicious app may be able to gain root privileges

Description: A permissions issue was addressed with additional restrictions.

CVE-2026-43689: Andreas Jaegersberger & Ro Achterberg of Nosebeard Labs

Kernel

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: Connecting to a malicious NFS server may disclose kernel memory

Description: The issue was addressed with improved memory handling.

CVE-2026-43687: R4mbb of KRsecurity, Peter Malone

Kernel

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: Connecting to a malicious NFS server may lead to kernel memory corruption

Description: A use-after-free issue was addressed with improved memory management.

CVE-2026-43686: Peter Malone

Kernel

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to determine kernel memory layout

Description: A memory initialization issue was addressed with improved memory handling.

CVE-2026-65405: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.

Kernel

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to disclose kernel memory

Description: An information disclosure issue was addressed with improved memory management.

CVE-2026-84530: Vladislav Shevchenko (Positive Technologies)

Kernel

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to cause unexpected system termination

Description: A use after free issue was addressed with improved memory management.

CVE-2026-84521: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.

CVE-2026-65402: Fábio Luís @scanpt, Richard Zana, Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.

Kernel

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: A local user may be able to cause unexpected system termination or read kernel memory

Description: An out-of-bounds read was addressed with improved bounds checking.

CVE-2026-65359: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.

Kernel

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to cause unexpected system termination or corrupt kernel memory

Description: A race condition was addressed with improved state handling.

CVE-2026-84507: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.

Kernel

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to disclose kernel memory

Description: An out-of-bounds read was addressed with improved input validation.

CVE-2026-86903: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.

Kernel

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to cause unexpected system termination

Description: A type confusion issue was addressed with improved checks.

CVE-2026-84602: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.

libarchive

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: Processing a maliciously crafted file may lead to unexpected app termination

Description: A heap buffer overflow was addressed with improved bounds checking.

CVE-2026-86870: Kitten Food

Managed Configuration

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to access sensitive user data

Description: A privacy issue was addressed with improved handling of files.

CVE-2026-86883: Sindre Sorhus, Morris Richman (@morrisinlife), Stuart Wallace, Tristan Brennan

MediaRemote

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: A sandboxed app may be able to access the System Keychain

Description: An authorization issue was addressed with improved state management.

CVE-2026-84628: Myeonghun Pak, Nathaniel Oh (@calysteon), Alan Banderas (@creeper4004)

MobileAccessoryUpdater

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: Connecting a malicious accessory may cause unexpected system termination

Description: A memory corruption issue was addressed with improved input validation.

CVE-2026-86924: Matthew Zamat

MobileBackup

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to modify protected parts of the file system

Description: A path handling issue was addressed with improved validation.

CVE-2026-65411: Rodolphe Brunetti (@eisw0lf) of Lupus Nova

MobileBackup

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An attacker with physical access to a trust-paired device may be able to read and write arbitrary files

Description: A path traversal issue was addressed with improved path validation.

CVE-2026-84598: Drin Raci of sentry.security

Model I/O

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: Opening a maliciously crafted file may lead to unexpected process termination

Description: A buffer overflow was addressed with improved size validation.

CVE-2026-84497: Yiğit Can YILMAZ (@yilmazcanyigit)

Music

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to access sensitive user data

Description: An authorization issue was addressed with improved state management.

CVE-2026-84615: Stanislav Jelezoglo

NetworkExtension

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to access sensitive user data

Description: An authorization issue was addressed with improved state management.

CVE-2026-43695: Claudio Bozzato and Francesco Benvenuto of Cisco Talos

NetworkExtension

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to identify what other apps a user has installed

Description: An information disclosure issue was addressed with improved state management.

CVE-2026-84626: Sindre Sorhus, Hoffcona of IES Red Team

Photos Storage

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to access sensitive user data

Description: A permissions issue was addressed with additional restrictions.

CVE-2026-84491: an anonymous researcher

Photos Storage

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to fingerprint the user

Description: This issue was addressed with additional entitlement checks.

CVE-2026-84629: Stanislav Jelezoglo

Power Management

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to fingerprint the device

Description: An authorization issue was addressed with improved state management.

CVE-2026-84623: Ilya Andr (andrd3v)

RealityKit

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: Processing a maliciously crafted file may lead to unexpected app termination

Description: An out-of-bounds write issue was addressed with improved bounds checking.

CVE-2026-28966: stratan (@5tratan)

RealityKit

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: Opening a maliciously crafted file may cause unexpected process termination or disclose process memory

Description: An out-of-bounds read issue was addressed with improved input validation.

CVE-2026-84532: Hongsik Kim (mnur), stratan (@5tratan)

Reminders

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to access sensitive user data

Description: This issue was addressed with improved checks.

CVE-2026-65403: Rahul Raj

Safari

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: A malicious website may be able to determine what apps a user has installed

Description: This issue was addressed through improved state management.

CVE-2026-84518: Bálint Magyar (balintmagyar.com)

Safe Browsing

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to access sensitive user data

Description: This issue was addressed with additional entitlement checks.

CVE-2026-86897: Stuart Wallace

Sandbox

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to bypass network restrictions

Description: A logic issue was addressed with improved validation.

CVE-2026-84551: Issa Sancho

Sandbox Profiles

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to fingerprint the user

Description: A permissions issue was addressed with additional sandbox restrictions.

CVE-2026-84625: Ilya Andr (andrd3v) of Positive Technologies, CJ Vana

Sandbox Profiles

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to access sensitive user data

Description: A permissions issue was addressed with additional restrictions.

CVE-2026-84603: Gongyu Ma (@Mezone0), CJ Vana, Stanislav Jelezoglo

SceneKit

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: Processing a maliciously crafted file may result in disclosure of process memory

Description: An integer overflow was addressed with improved input validation.

CVE-2026-84487: stratan (@5tratan), Dhiyanesh Selvaraj (@redroot97), Peter Malone

SceneKit

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: Processing a maliciously crafted 3D model may lead to memory corruption

Description: The issue was addressed with improved memory handling.

CVE-2026-84632: Peter Malone

SceneKit

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: Processing a maliciously crafted 3D model may lead to memory corruption

Description: An integer overflow was addressed with improved input validation.

CVE-2026-84620: Peter Malone

SceneKit

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: Processing a maliciously crafted 3D model may lead to memory corruption

Description: An out-of-bounds write issue was addressed with improved bounds checking.

CVE-2026-84546: Narendra Singh (@_3P1C), stratan (@5tratan), Peter Malone

CVE-2026-84611: Nathaniel Oh (@calysteon)

SceneKit

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: Processing a maliciously crafted 3D scene may lead to unexpected process termination

Description: An out-of-bounds write issue was addressed with improved bounds checking.

CVE-2026-84526: stratan (@5tratan)

Security

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An attacker with a compromised intermediate certificate authority may be able to issue certificates with arbitrary extended key usages

Description: A certificate validation issue was addressed with improved certificate validation.

CVE-2026-86881: Surya Narayan Kushwaha, Roman Zabicki, John Lussier, Filip Olszak

Security

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: Processing maliciously crafted NTLM input may lead to unexpected app termination

Description: An out-of-bounds write issue was addressed with improved bounds checking.

CVE-2026-84531: Meshaal (@unrealmesh)

Shortcuts

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: A malicious shortcut may be able to send messages without user confirmation

Description: An authorization issue was addressed with improved state management.

CVE-2026-84600: Owen Pawling (@owenpawling)

Siri

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to access sensitive user data

Description: A permissions issue was addressed with additional restrictions.

CVE-2026-86884: Stanislav Jelezoglo, Gongyu Ma (twitter @Mezone0)

Siri Suggestions

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An attacker with physical access to a locked device may be able to view sensitive user information

Description: A logic issue was addressed with improved checks.

CVE-2026-86890: Abhay Kailasia (@abhay_kailasia) from Safran Mumbai India

Software Update

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to modify protected system files

Description: A permissions issue was addressed with improved path validation.

CVE-2026-84609: YingMuo (@YingMuo) of DEVCORE Research Team

Spotlight

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to access sensitive user data

Description: An authorization issue was addressed with improved access control.

CVE-2026-84621: Abodi Dawoud, Armend Gashi, Ujjwal Reddy Kalvolu Sreenivasa Reddy, Johan Wahyudi

SpringBoard

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to cause a denial-of-service

Description: This issue was addressed with additional entitlement checks.

CVE-2026-86892: Lehan Dilusha Jayasingha

Storage

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to modify protected parts of the file system

Description: A permissions issue was addressed with additional restrictions.

CVE-2026-65348: Jérôme Djouder

Storage

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to access user-sensitive data

Description: A permissions issue was addressed with additional restrictions.

CVE-2026-65345: Seung Je Seong, Ilya Andr (andrd3v) of Positive Technologies, Jakob Pammer, 이재영

Symptom Framework

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: A malicious application may be able to determine a user's current location

Description: A privacy issue was addressed with improved private data redaction for log entries.

CVE-2026-84513: Sindre Sorhus

TCC

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to modify protected system files

Description: A path traversal issue was addressed with improved input validation.

CVE-2026-86886: Constantin Clerc, Shad J, huami1314 (@huamidev), Huy Nguyen (@34306) of Calif.io, an anonymous researcher

TCC

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to access sensitive user data

Description: A logging issue was addressed with improved data redaction.

CVE-2026-84527: Zeyang Li&Yuxiang Wang of Chongqing Telecom

Telephony

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An attacker in a privileged network position may be able to bypass IPSec authentication and intercept network traffic

Description: An authentication issue was addressed with improved state management.

CVE-2026-65329: Bedran Karakoc, Tobias Funke, Jacopo Clark, Katharina Kohls of Ruhr University Bochum

Time Zone

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to bypass certain Privacy preferences

Description: A privacy issue was addressed by removing sensitive data.

CVE-2026-86887: an anonymous researcher

Watch App

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to track users across apps and websites without permission

Description: A privacy issue was addressed with improved state management.

CVE-2026-86904: Stanislav Jelezoglo

WebKit

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: Processing maliciously crafted web content may lead to an unexpected process termination

Description: A logic issue was addressed with improved state management.

WebKit Bugzilla: 310457

CVE-2026-84635: Souta Sugiyama

WebKit

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: Processing maliciously crafted web content may disclose sensitive user information

Description: A permissions issue was addressed by removing the vulnerable code.

WebKit Bugzilla: 315121

CVE-2026-64753: Viggo Lekdorf

WebKit

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: Opening a maliciously crafted webarchive file may lead to universal cross-site scripting

Description: A logic issue was addressed with improved state management.

WebKit Bugzilla: 318271

CVE-2026-86898: Tomi Garcia (archyxsec)

WebKit Canvas

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash

Description: A use-after-free issue was addressed with improved memory management.

WebKit Bugzilla: 313935

CVE-2026-64718: Niels Hofmans, OGINOME Tomohito, an anonymous researcher

Wi-Fi3

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An attacker with physical access to an unlocked device may be able to view Wi-Fi passwords without authentication

Description: An authentication issue was addressed with improved state management.

CVE-2026-43674: Yusuf Kelany

Wi-Fi Connectivity

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to access sensitive user data

Description: An authorization issue was addressed with improved state management.

CVE-2026-84636: Jian Lee (@speedyfriend433)

XPC

Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later

Impact: An app may be able to access sensitive user data

Description: An authorization issue was addressed with improved state management.

CVE-2026-84617: Stuart Wallace

Additional recognition

Accessibility

We would like to acknowledge Abhay Kailasia (@abhay_kailasia) from Safran Mumbai India for their assistance.

Accounts

We would like to acknowledge Wojciech Regula of SecuRing (wojciechregula.blog) for their assistance.

Apple Intelligence

We would like to acknowledge an anonymous researcher for their assistance.

AppleKeyStore

We would like to acknowledge Abdurrahman Nafi, Francisco Knabe, Karol Mazurek (@Karmaz95) of AFINE, Somair Ansar, YOKI, an anonymous researcher, 晓娟 谢 for their assistance.

Audio

We would like to acknowledge Dhiyanesh Selvaraj (@redroot97) for their assistance.

AutoFill

We would like to acknowledge Bistrit Dahal, Oussama Barbar, SalahAldeen Yousef for their assistance.

AVEVideoEncoder

We would like to acknowledge tamdao for their assistance.

Baseband

We would like to acknowledge Kai Tu, Tianchang Yang, Xiaotian Zhou, Ali Ranjbar, Abdullah Al Ishtiaq, Tianwei Wu, Yilu Dong, Syed Rafiul Hussain — SyNSec Lab at Penn State for their assistance.

Bluetooth

We would like to acknowledge David Maynor, Jason Grove, Suresh Sundaram, Youssef Ahmed Saad, jioundai for their assistance.

BOM

We would like to acknowledge 2ourc3 | Salim Largo for their assistance.

Calendar

We would like to acknowledge Atul Kishor Jaiswal, Dany Assuid, Jacob Hazak from Zero-Defense Labs, Varik Matevosyan, stratan (@5tratan) for their assistance.

CipherML

We would like to acknowledge Nils Hanff (@nils1729@chaos.social) of Hasso Plattner Institute for their assistance.

CloudKit

We would like to acknowledge Ahmed Alwardani, Hikerell (Loadshine Lab) for their assistance.

Contacts

We would like to acknowledge 이지안 (@speedyfriend433) for their assistance.

copyfile

We would like to acknowledge Morris Richman (@morrisinlife) and Jian Lee (@speedyfriend433) for their assistance.

Core Location

We would like to acknowledge CJ Vana for their assistance.

CoreAnimation

We would like to acknowledge Duy Trần (@khanhduytran0) for their assistance.

CoreAudio

We would like to acknowledge Patrick Saif / x.com/weezerOSINT / github.com/sai2fast for their assistance.

CoreBluetooth - LE

We would like to acknowledge Ashmit Sharma & Atul RV, Dun, Maliq Barnard, Nicholas C. of Onymos Inc. (onymos.com), Peter Malone, Robert M for their assistance.

CoreCrypto

We would like to acknowledge Lakshay Sharma for their assistance.

CoreGraphics

We would like to acknowledge Gandalf4a of PKU-Changsha Institute for Computing and Digital Economy for their assistance.

CoreMedia

We would like to acknowledge Chris Bailey - Short Circuit for their assistance.

CoreText

We would like to acknowledge Chris Bailey - Short Circuit, Jian Lee (@speedyfriend433), shobhit srivastav for their assistance.

CoreUI

We would like to acknowledge Peter Malone for their assistance.

DataAccess

We would like to acknowledge Adetayo Adebimpe (Cyboghostginx) for their assistance.

DiskArbitration

We would like to acknowledge Arni Hardarson (Neonix Security), FRO, Mustafa Ahmed, Thomas Guillem, 九宫格 of Chongqing Telecom for their assistance.

FaceTime

We would like to acknowledge Souhaib Naceri for their assistance.

Files

We would like to acknowledge an anonymous researcher for their assistance.

Foundation

We would like to acknowledge Daniel Luedke, Pavan Nallamothu, Peter Malone, Tiago "Balgan" Henriques for their assistance.

HFS

We would like to acknowledge an anonymous researcher for their assistance.

iCloud

We would like to acknowledge 3ndy1(@_3ndy1) and moyu for their assistance.

iCloud Photo Library

We would like to acknowledge an anonymous researcher for their assistance.

ImageIO

We would like to acknowledge Muhamad Syaiful, an anonymous researcher, songbird for their assistance.

IOMobileFrameBuffer

We would like to acknowledge Iain Harkiss, Jian Lee (@speedyfriend433) for their assistance.

IOSurface

We would like to acknowledge N.M.Praveen Nawarathne (@zblockrat), ธนกฤต ทัฬหะ for their assistance.

IOSurfaceAccelerator

We would like to acknowledge Chanwit Muenprakoddee (ChemIndy), Franco Belman at Blackwing Intelligence, Iain Harkiss, an anonymous researcher, beist, hxr1 for their assistance.

Kernel

We would like to acknowledge Bhaswanth Chigurupati, Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd., Cem Onat Karagun, DARKNAVY (@DarkNavyOrg), James Duffy (@0x4A616D657344), Kang Sangkwun, Lyutoon, N.M.Praveen Nawarathne (@zblockrat), Nebula Security (@nebusecurity), Nicolas Seriot, Peter Malone, Redon Gashi of Sentry, Robert Tran, Tristan Madani (@TristanInSec) from Talence Security, Xiang Li from AOSP Lab @Nankai University, an anonymous researcher for their assistance.

LaunchServices

We would like to acknowledge Rosyna Keller of Totally Not Malicious Software (paradisefacade.com) for their assistance.

mDNSResponder

We would like to acknowledge Anton Pakhunov, Franciszek Kalinowski (striga.ai / isec.pl), Hannes Weissteiner, Roland Czerny, Simone Franza, Stefan Gast and Daniel Gruss of Graz University of Technology, and Johanna Ullrich of the Interdisciplinary Transformation University (IT:U), Issa Sancho, Jian Zhou, 章鱼哥@aipy (aipyaipy.com) for their assistance.

Messages

We would like to acknowledge Pratyush Dutta for their assistance.

Notes

We would like to acknowledge Peter Henri for their assistance.

Notifications

We would like to acknowledge Abhay Kailasia (@abhay_kailasia) from Safran Mumbai India, Himanshu Bharti @Xpl0itme From Khatima, Jan Rokita (rokita.me) for their assistance.

PaperKit

We would like to acknowledge Rahul Raj for their assistance.

Passwords

We would like to acknowledge Catalin Lita of Moralis, Christian Kohlschütter, David Coomber of Info-Sec.CA, Lukasz Tulikowski at Software Cloud, Sujay Amin, an anonymous researcher for their assistance.

ppp

We would like to acknowledge Cem Onat Karagun for their assistance.

Printing

We would like to acknowledge Stuart Wallace for their assistance.

Pro Res

We would like to acknowledge Meta Red Team X - Nik Tsytsarkin for their assistance.

Quick Look

We would like to acknowledge Peter Malone for their assistance.

RemoteServiceDiscovery

We would like to acknowledge Tristan Madani (@TristanInSec) from Talence Security, an anonymous researcher for their assistance.

Safari

We would like to acknowledge Dem0ns @天府简易信工作室 for their assistance.

Safari Downloads

We would like to acknowledge Barath Stalin K (linkedin.com/in/barathstalin), Exell Nakano, Manojkumar Jaganathan (linkedin.com/in/manojkumar-j-7ba35b202/) with HackerBro Technologies, Praditya Fajar Ramadhan, Zhiyang Zeng (@Wester), shobhit srivastav for their assistance.

Safari Extensions

We would like to acknowledge Jake Derouin (jakederouin.com) for their assistance.

Sandbox Profiles

We would like to acknowledge Lachlan Bauerochse for their assistance.

Security

We would like to acknowledge John Lussier, Masahiro Kawada (@kawakatz), Roman Zabicki for their assistance.

Settings

We would like to acknowledge an anonymous researcher for their assistance.

Share Sheet

We would like to acknowledge Atul Kishor Jaiswal, Benjamin Hornbeck for their assistance.

Shortcuts

We would like to acknowledge Csaba Fitzl (@theevilbit) of Iru, GP, Owen Pawling (@owenpawling) for their assistance.

Status Bar

We would like to acknowledge Andr.Ess, Rosyna Keller of Totally Not Malicious Software for their assistance.

Terminal

We would like to acknowledge Stuart Thomas for their assistance.

UIKit

We would like to acknowledge Jorge Welch for their assistance.

Virtualization

We would like to acknowledge Ye Zhang (@VAR10CK) of Baidu Security for their assistance.

VoiceOver

We would like to acknowledge Hariji Vivek Pandey for their assistance.

WebKit

We would like to acknowledge @TristanInSec, Behzad Najjarpour Jabbari (@_G4ru_), Big Bear, Eddy Tsalolikhin, Henock Habte, Kenneth Hsu, Maher Azzouzi, Meridian Miftari, OpenAI Codex Security - Amy Burnett, Souta Sugiyama, Vitaly Simonovich, an anonymous researcher, hamayanhamayan, lattice, ret2happy, wwwlk for their assistance.

WebKit Canvas

We would like to acknowledge Utkarsh Pal for their assistance.

WebKit JavaScript Bindings

We would like to acknowledge hamayanhamayan for their assistance.

Wi-Fi

We would like to acknowledge E Vestavik (@Dynasty) for their assistance.

Widgets

We would like to acknowledge Vishnu Prasad P G & Akshaya S, an anonymous researcher for their assistance.

Information about products not manufactured by Apple, or independent websites not controlled or tested by Apple, is provided without recommendation or endorsement. Apple assumes no responsibility with regard to the selection, performance, or use of third-party websites or products. Apple makes no representations regarding third-party website accuracy or reliability. Contact the vendor for additional information.

公開日: