Executive brief
A privacy vulnerability in iPhone and iPad software could allow someone with physical access to a device to view sensitive user information. This occurs specifically when using the Visual Intelligence feature during iPhone Mirroring. An attacker must have the device in their hands to exploit this flaw, which could lead to the exposure of private data.
Technical details
A privacy issue existed in the implementation of Visual Intelligence when used in conjunction with iPhone Mirroring. The vulnerability allowed an attacker with physical access to the device to bypass intended data protections and access sensitive user information. Apple addressed the issue by removing the vulnerable code path. The fix is available in iOS 26.5 and iPadOS 26.5. This vulnerability is tracked as CVE-2026-28963.
Affected products
- Apple iOS Before 26.5
- Apple iPadOS Before 26.5
Timeline
- 2026-05-11: disclosed
- 2026-05-11: patched