Junglewise Threat Intelligence

CVE-2026-28963: Apple iOS and iPadOS privacy bypass in iPhone Mirroring

CVE-2026-28963 · Severity: medium · CVSS 4.6 · Published 2026-05-11

Technologies: Apple Iphone Os, Apple iPadOS. Vendors: Apple.

Executive brief

A privacy vulnerability in iPhone and iPad software could allow someone with physical access to a device to view sensitive user information. This occurs specifically when using the Visual Intelligence feature during iPhone Mirroring. An attacker must have the device in their hands to exploit this flaw, which could lead to the exposure of private data.

Technical details

A privacy issue existed in the implementation of Visual Intelligence when used in conjunction with iPhone Mirroring. The vulnerability allowed an attacker with physical access to the device to bypass intended data protections and access sensitive user information. Apple addressed the issue by removing the vulnerable code path. The fix is available in iOS 26.5 and iPadOS 26.5. This vulnerability is tracked as CVE-2026-28963.

Affected products

  • Apple iOS Before 26.5
  • Apple iPadOS Before 26.5

Timeline

  • 2026-05-11: disclosed
  • 2026-05-11: patched

References

Related threats